Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Secret scanning detects secrets in GitHub discussions and pull request content #965

Open
github-product-roadmap opened this issue May 29, 2024 · 1 comment
Labels
ga Feature phase: Generally available GHES 3.15 GHES 3.15 github advanced security Product SKU: GitHub Advanced Security secret scanning Feature: Github Secret Scanning shipped Shipped

Comments

@github-product-roadmap
Copy link
Collaborator

Summary

Secret scanning is expanding detection coverage beyond commit content. GitHub now detects secrets found in pull request and GitHub discussions (e.g. bodies, comments, edits).

As GitHub expands support, GitHub will be performing backfills to detect historically existing secrets across pull requests and discussions.

This release follows support of scanning for GitHub issues, and will be similarly followed by support for secret scanning across GitHub wiki content.

Intended Outcome

Secrets can be exposed anywhere -- not just across code content. GitHub helps keep you safe by automatically scanning additional surfaces across GitHub, without the need for any additional setup.

How will it work?

For repositories where secret scanning is enabled, you'll automatically begin to receive secret scanning alerts for any exposed secrets in pull requests or discussions. GitHub will also continue to scan public repositories for publicly leaked secrets, and will now notify partners in secret scanning's partnership program if secrets are detected in public pull requests or discussions.

@github github locked and limited conversation to collaborators May 29, 2024
@github-product-roadmap github-product-roadmap added ga Feature phase: Generally available GHES 3.15 GHES 3.15 github advanced security Product SKU: GitHub Advanced Security secret scanning Feature: Github Secret Scanning labels May 29, 2024
@ankneis
Copy link
Collaborator

ankneis commented Sep 20, 2024

🚢 This has shipped: https://github.blog/changelog/2024-08-16-secret-scanning-for-non-code-github-surfaces-is-now-generally-available/

Leaving open to track for GHES release.

@ankneis ankneis added the shipped Shipped label Sep 20, 2024
# for free to subscribe to this conversation on GitHub. Already have an account? #.
Labels
ga Feature phase: Generally available GHES 3.15 GHES 3.15 github advanced security Product SKU: GitHub Advanced Security secret scanning Feature: Github Secret Scanning shipped Shipped
Projects
Development

No branches or pull requests

2 participants