HomeSecurityGitHub: Automatically blocks commits containing API keys

GitHub: Automatically blocks commits containing API keys

According to a recent announcement from GitHub, the code hosting platform's secrets scanning capabilities for GitHub Advanced Security have been expanded to automatically block leaks.

See also: More security vulnerabilities found by GitHub code scan

GitHub

Secret scanning is an advanced security option that organizations using GitHub Enterprise Cloud with a GitHub Advanced Security for additional repository scanning.

It works by matching patterns defined by the organization or provided by partners and service providers. Each match is reported as a security alert in the Security tab of repos or to partners if it matches a partner pattern.

The new feature, known as push protection, is designed to prevent accidental exposure of credentials before committing code to remote repositories.

This new feature integrates stealth scanning into developers’ workflows and works with 69 token types (API keys, authentication tokens, access tokens, management certificates, credentials, private keys, secret keys, and more) that can be detected with a low “false positive” detection rate.

If GitHub Enterprise Cloud detects a secret before pushing the code, git push is blocked to allow developers to review and remove the secrets from the code they attempted to push to remote repos.

See also: Microsoft Sentinel: Acquires threat monitoring for GitHub repos

Developers can also mark these security alerts as false positives, test cases, or flag them for later remediation.

Organizations with GitHub Advanced Security can enable push scan secret protection at both the repository and organization level via the API or with a single click from the user interface.

excludes commitments

The detailed process for enabling push protection for your organization requires:

  1. On GitHub.com, go to the organization's main page.
  2. Under your organization name, click Settings.
  3. In the “Security” section of the sidebar, click Security and Code Analysis.
  4. In the “Security and Code Analysis” section, find “GitHub Advanced Security.”
  5. In the “ Secret Scan ” section , under “ Push Protection ”, click Enable All .
  6. Optionally, click “Automatically enable for private repositories added to secret scan.”

See also: How to delete a branch on GitHub

You can find more information about the secret scan capabilities here and additional details on how to use push protection from the command line or allow certain secrets to be pushed here.

You can also enable it for individual repositories by enabling it from the Settings > Security and analytics > GitHub Advanced Security dialog .

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS