Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Secret scanning (Server Beta) #57

Open
github-product-roadmap opened this issue Jul 24, 2020 · 0 comments
Open

Secret scanning (Server Beta) #57

github-product-roadmap opened this issue Jul 24, 2020 · 0 comments

Comments

@github-product-roadmap
Copy link
Collaborator

@github-product-roadmap github-product-roadmap commented Jul 24, 2020

Summary
This feature extends support for secret scanning to private and public repositories on server. For server, GitHub does not automatically send a request to the issuer to revoke the checked-in token. Instead, results are displayed to repo/org admins in the GitHub UI for them to triage.

Intended Outcome
Token leaks are one of the most common security mistakes, and they can have severe consequences. GitHub secret scanning already looks for leaked tokens in public repositories and works with the token-issuer to notify the developer and in some cases automatically revoke the token.

How will it work?
Secret scanning for Server will provide more configuration, including the ability to exclude paths and files using config-as-code. In future it will also provide reporting at the organization level.

@github github locked and limited conversation to collaborators Jul 24, 2020
@github-product-roadmap github-product-roadmap added this to Q4 2020 – Oct-Dec in GitHub public roadmap Jul 24, 2020
@github-product-roadmap github-product-roadmap changed the title Secret scanning for private repositories (Server) Secret scanning (Server Beta) Oct 7, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
GitHub public roadmap
Q4 2020 – Oct-Dec
Linked pull requests

Successfully merging a pull request may close this issue.

None yet
1 participant
You can’t perform that action at this time.