logo

GitHub enables push protection by default to stop secrets leak

ID: 137485a2-ce83-52ea-91d4-3ac3a48d22d3

STIX ID: report--137485a2-ce83-52ea-91d4-3ac3a48d22d3

Feed Name: Bleeping Computer

Date Published: 2024-02-29

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

GitHub is rolling out default push protection for all public repositories, proactively scanning and blocking commits that contain secrets (API keys, tokens, certificates, etc.) across 200+ token types from 180+ providers before a git push is accepted; users can remove the secret or bypass, and organizations with Enterprise gain additional Advanced Security capabilities. The rollout may take 1–2 weeks per account, and GitHub underscores the need by noting over 1 million leaked secrets were detected on public repos in the first eight weeks of 2024, with documentation available for CLI workflows and allowlisting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.