AppSecNews
Secret Scanning Commercial, free tier Established

GitHub Secret Scanning

by GitHub

GitHub's built-in scanner that matches partner-registered credential patterns on push, can block the push outright, and notifies issuing providers so they can revoke.

Visit docs.github.com (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run GitHub Secret Scanning in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 2 points in this profile are not yet confirmed against vendor documentation.
  • Which capabilities sit in the free public-repository tier versus the paid product: confirm against current documentation
  • Current partner list and validity-check coverage: confirm against documentation

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

GitHub Secret Scanning matches pushed content against patterns supplied by the credential issuers themselves. Providers join a partner program and register the exact format of their tokens, often including a checksum or prefix that makes the match precise rather than heuristic. When a match lands, the provider is notified with the matched string so they can revoke it, often before the repository owner has read the alert. That feedback loop is what distinguishes it from a scanner you run yourself.

Push protection is the preventive half. With it enabled the scan runs before the push is accepted and rejects it when a recognized credential appears, with a documented bypass path recording who overrode it and why. Scanning covers repository content and history, and for several providers a validity check tells you whether the token still works. Custom patterns cover an organization's own credential formats, with a dry run to gauge match volume before enabling. Public repositories are covered in the free tier; private repositories and the administrative controls sit in GitHub's paid security product.

Where it fits

This runs at the platform boundary, the moment code reaches GitHub, the last place to intervene before an artifact is durable. Nobody deploys it; an administrator enables it at the organization level and configures push protection and custom patterns. Developers meet it as a blocked push. It presumes your code lives on GitHub and that you accept the bypass workflow when a match is wrong.

Strengths

  • Partner-registered patterns are precise, so alert volume is far lower than an entropy-based scanner produces.
  • Provider notification means a leaked token can be revoked automatically, shortening exposure to a window rather than a triage backlog.
  • Push protection is a genuine preventive control with an audited bypass, not just detection after the fact, and there is nothing to operate.

Limitations

  • Coverage is bounded by the partner program. Credentials from unregistered providers, and any homegrown token format, are missed unless you write custom patterns.
  • Custom patterns and private repository scanning sit in the paid security product rather than the free public-repository tier.
  • It is GitHub only, so a mixed estate needs a second tool anyway and rule parity across the two becomes your problem. Bypasses also depend on someone reviewing the bypass records.

Who it suits

Any organization hosting on GitHub should turn this on, since the preventive value and automatic revocation are hard to replicate. It is enough alone for a team whose secrets come from major SaaS providers. Teams with internal credential formats, multiple hosting platforms, or a need to evidence detection independently of the host will want a dedicated scanner alongside it.

Used GitHub Secret Scanning? Recommend it under your own name and title.

Recommend this tool