Skip to content

Pinterest is now a GitHub secret scanning partner

GitHub secret scanning protects users by searching repositories for known types of secrets. By identifying and flagging these secrets, our scans help prevent data leaks and fraud.

We have partnered with Pinterest to scan for their API tokens and help secure our mutual users on public repositories. Pinterest tokens allow developers to interact with Pinterest's API in order to build experiences and apps for creators, advertisers, merchants and users on top of Pinterest. GitHub will forward access tokens found in public repositories to Pinterest, which will then notify the user about the leaked token. You can read more information about Pinterest tokens here.

All users can scan for and block Pinterest's tokens from entering their public repositories for free with push protection. GitHub Advanced Security customers can also scan for and block Pinterest tokens in their private repositories.

GitHub Advanced Security customers that have validity checks enabled will see the validation status for select AWS, Google, Microsoft, and Slack tokens on the alert.

The following tokens are supported:

  • aws_access_key_id
  • aws_secret_access_key
  • aws_session_token
  • aws_temporary_access_key_id
  • aws_secret_access_key
  • google_oauth_access_token
  • google_api_key
  • nuget_api_key
  • slack_api_token

AWS tokens will have validation checks performed periodically in the background, with on-demand validity checks to come in the future.

View our supported secrets documentation to keep up to date as we expand validation support.

See more

GitHub Sponsors is now available in 35 new regions! You can now sign up for Sponsors if you have a bank account and tax residence in any of the following regions:

  • Albania
  • Antigua & Barbuda
  • Armenia
  • Bahrain
  • Bosnia & Herzegovina
  • Cambodia
  • Côte d’Ivoire
  • Ecuador
  • El Salvador
  • Ethiopia
  • Ghana
  • Guatemala
  • Guyana
  • Jamaica
  • Jordan
  • Kuwait
  • Macao SAR China
  • Madagascar
  • Malaysia
  • Mauritius
  • Moldova
  • Mongolia
  • Namibia
  • Nigeria
  • North Macedonia
  • Oman
  • Panama
  • Qatar
  • Rwanda
  • Senegal
  • Sri Lanka
  • St. Lucia
  • Tanzania
  • Uzbekistan and Vietnam

You can sponsor projects from wherever GitHub does business and join the Sponsors waitlist if we’re not yet in your region.

See more