GitHub secret scanning now detects and alerts you on secrets found in GitHub issues, wikis, discussions, and pull requests.
Secrets, like API keys, passwords, and tokens, can hide in many places. Throughout 2024, we’ve discovered over 100k unique secrets hiding in mediums outside of code. If these leaks aren’t managed correctly, each one of them could pose a substantial risk.
To help protect you from leaked secrets – anywhere within your GitHub perimeter – GitHub provides visibility across all major surfaces. We scan these surfaces for over 200+ token formats and work with relevant partners to help protect you from publicly leaked secrets. GitHub also supports generic patterns like RSA private keys and Copilot-detected passwords.
Learn more about how to secure your repositories with secret scanning.
Let us know what you think by participating in a GitHub community discussion or signing up for a 60 minute feedback session.