Saturday, April 1, 2023
  • Events
  • Interviews
  • Jobs
  • Opinion
  • Whitepapers
  • Podcasts
  • Web Hosting Directory
  • Login
  • Register
Cloud7
  • Cloud Computing
  • Web Hosting
  • Data Center
  • Linux
  • Cybersecurity
  • More
    • Software
    • Network/Internet
    • Hardware
    • Artificial Intelligence
    • Windows
    • Policy/Legislation
    • Blockchain
    • Troubleshooting
    • How-Tos
    • Articles
No Result
View All Result
Cloud7
  • Cloud Computing
  • Web Hosting
  • Data Center
  • Linux
  • Cybersecurity
  • More
    • Software
    • Network/Internet
    • Hardware
    • Artificial Intelligence
    • Windows
    • Policy/Legislation
    • Blockchain
    • Troubleshooting
    • How-Tos
    • Articles
No Result
View All Result
Cloud7
No Result
View All Result

Home > Cybersecurity > GitHub releases secret scanning alerts for security

GitHub releases secret scanning alerts for security

For security reasons, GitHub issues secret scanning alerts to inform users if there are secrets in their codes.


Ezgi Koc Ezgi Koc
March 9, 2023
2 min read
GitHub releases secret scanning alerts for security
  • GitHub now offers free secret scanning alerts that scan code, description, and other parts, which can be enabled manually.
  • A DevOps consultant and trainer who enabled secret scanning on roughly 14,000 repositories reported finding about a thousand secrets, and he even claimed to have discovered secrets in his own code.
  • Secret scanning alerts can be enabled by any owner or administrator of a public repository, and enterprise administrators and organization owners can also bulk-enable alerts for numerous repositories.

Back in December, the GitHub team launched the beta version of the free secret scanning alerts across public repositories and now it is generally available and free for all public repositories. When you enable secret scanning alerts across all of your repositories, including code, problems, descriptions, and comments, they will warn you of any secrets that have been compromised. GitHub secret scanning will alert its partners if any of their secrets have been leaked as well as when there isn’t a partner to alert, such as if self-hosted keys are exposed.

No secrets leaked

Around a thousand secrets were found by a DevOps consultant and trainer who enabled secret scanning on about 14,000 repositories. He said:

« My research proves the point to why everyone should have secret scanning enabled. I have researched 14 thousand public GitHub Action repositories and found over one thousand secrets in them! Even though I train a lot of folks on using GitHub Advanced Security, I found secrets in my own repositories through this. Despite multiple years of experience, it also happens to myself. That’s how easy it is to include secrets by mistake. »

The goal of secret scanning is to prevent unintentional exposure of sensitive information in public repositories by identifying and alerting if potential secrets are found, which reduces the chances of mistakes that could be costly. By doing this, GitHub makes sure that the problems are stopped before they can create dire consequences.

How to get the alerts

Any owner or admin of a public repository can enable secret scanning alerts. Enterprise administrators and organization owners can also bulk-enable alerts for multiple repositories. You can do this by going to the Settings tab and clicking on Code security and analysis under Security. Find Secret scanning and click Enable.

Secret scanning enabling.

See more Cybersecurity News

A comprehensive guide to understanding Cybersecurity: What is Cybersecurity?


Tags: GitHub
Ezgi Koc

Ezgi Koc

Ezgi Koc is an editor at Cloud7. She graduated from Ege University with a bachelor's degree in English Language and Literature. She has always had great interest in technology, both hardware and software, since her childhood and decided to pursue a career that would enable her to broaden her horizons in this field. She is very passionate about video games as a Twitch affiliate and streams games in her free time.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

Next Post
GoDaddy to shut down Uniregistry Market

GoDaddy to shut down Uniregistry Market

Related News

7 best practices and tools to use for Linux security

7 best practices and tools to use for Linux security

March 24, 2023 5:00 pm
CISA aims to identify vulnerabilities that attract ransomware

CISA aims to identify vulnerabilities that attract ransomware

March 22, 2023 2:10 pm
7 best cybersecurity schools

7 best cybersecurity schools

March 21, 2023 9:00 pm
Akamai researchers warn about the new HinataBot botnet

Akamai researchers warn about the new HinataBot botnet

March 20, 2023 6:10 pm
Get free daily newsletters from Cloud7 News Get the Cloud7 Newsletter
Select list(s):

Check your inbox or spam folder to confirm your subscription.

By subscribing, you agree to our
Copyright Policy and Privacy Policy

Get the free newsletter

Subscribe to receive the latest IT business updates straight to your inbox.

Select list(s):

Check your inbox or spam folder to confirm your subscription.

Recent News

  • How to take a screenshot on Windows 11
  • 7 games you can play on the Linux terminal
  • Leostream announces hybrid cloud environments with WorkSpaces Core
  • Now you can move Yandex Mail to ispmanager
  • 7 best SEO plugins for WordPress

Cloud7 News
Cloud7 is a news source that publishes the latest news, reviews, comparisons, opinions, and exclusive interviews to help tech users of high-experience levels in the IT industry.

EXPLORE

  • Web Hosting
  • Cloud Computing
  • Data Center
  • Cybersecurity
  • Linux
  • Network/Internet
  • Software
  • Hardware
  • Artificial Intelligence
  • How-Tos
  • Troubleshooting

RESOURCES

  • Events
  • Interviews
  • Jobs
  • Opinion
  • Whitepapers
  • Podcasts
  • Web Hosting Directory

Get the Cloud7 Newsletter

Get FREE daily newsletters from Cloud7 delivering the latest news and reviews.

  • About Us
  • Privacy & Policy
  • Copyright Policy
  • Contact

© 2023, Cloud7 News. All rights reserved.

No Result
View All Result
  • Cloud Computing
  • Web Hosting
  • Data Center
  • Linux
  • Cybersecurity
  • More
    • Software
    • Network/Internet
    • Hardware
    • Artificial Intelligence
    • Windows
    • Policy/Legislation
    • Blockchain
    • Troubleshooting
    • How-Tos
    • Articles
  • Events
  • Interviews
  • Jobs
  • Opinion
  • Whitepapers
  • Podcasts
  • Web Hosting Directory

© 2023, Cloud7 News. All rights reserved.

Welcome Back!

Sign In with Facebook
Sign In with Google
Sign In with Linked In
OR

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Sign Up with Facebook
Sign Up with Google
Sign Up with Linked In
OR

Fill the forms below to register

*By registering into our website, you agree to the Terms & Conditions and Privacy Policy.
All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.