GitHub secret scanning protects users by searching repositories for known types of secrets. By identifying and flagging these secrets, our scans help prevent data leaks and fraud.
We have partnered with Grafana Labs to scan for their tokens and help secure our mutual users on public repositories. Grafana tokens allow users to manage all resources within Grafana installations, and Grafana Cloud tokens can be used to authorize data ingestion requests and to manage the lifecycle of stacks. GitHub will forward access tokens found in public repositories to Grafana Labs, and they will automatically revoke the token and notify affected customers. You can read more information about Grafana's various tokens below:
- Grafana Service Account tokens
- Grafana API keys
- Grafana Cloud API keys
- Grafana Cloud Access Policies tokens
GitHub Advanced Security customers can also scan for Grafana tokens and block them from entering their private and public repositories with push protection.