HomeSecurityGitHub: Updates Advanced Security for more security

GitHub: Updates Advanced Security for more security

GitHub is updating its Advanced Security platformafter discovering 39 million exposed secrets in repositories in 2024, including API keys and credentials. These leaks put users and organizations at serious risk.

GitHub Advanced Security leaks secrets

In a new report, GitHub says the 39 million secrets were found through its secret scanning service, which detects API keys, passwords, tokens, and other secrets in repositories.

“ Leaks remain one of the most common—and preventable—causes of security incidents ,” GitHub reports . “ As we develop code faster than ever, we leak secrets faster than ever .”

GitHub already implements some targeted protection measures, such as “Push Protection”, which is enabled by default on all public repositories, starting in February 2024. Nevertheless, leaks still appear to be possible.

See also: Coinbase was the target of GitHub Actions breaches

According to GitHub, the main reasons why secrets continue to leak are:

  • the fact that developers handle secrets during commits
  • the "accidental" exposure of the repository via git history

GitHub: Updates Advanced Security for more security

GitHub announced several new measures and improvements to existing systems to limit secret leaks.

“Starting today, our security products are available for purchase as standalone products for enterprises, enabling development teams to quickly increase security,” GitHub explained.

“Previously, investing in secret scanning and push protection required purchasing a larger suite of security tools, making it too expensive for many organizations… This change ensures scalable security with Secret Protection and Code Security no longer out of reach for many organizations.“.

See also: Fake GitHub “Security Alert” compromises accounts via OAuth

Below, you can see a summary of the improvements coming to GitHub Advanced Security:

  • Standalone Secret Protection and Code Security: The features are now available as separate products and do not require a full GitHub Advanced Security license. This means they are much more affordable and can be more easily leveraged by smaller teams.
  • Free organization-wide secret risk assessment: With the GitHub Advanced Security update, a timely scan is available that checks all repositories (public, private, internal, and archived) for exposed secrets. It is provided free of charge to all GitHub organizations.
  • Secret detection powered by Copilot: GitHub now uses artificial intelligence, powered by Copilot, to detect unstructured secrets like passwords, improving accuracy and reducing false positives.
  • Push protection with delegated bypass controls: Thanks to an improvement to Push protection, it is possible to scan for secrets before pushing code and allows organizations to define who can bypass protection, adding policy-level controls.
  • Improved detection through partnerships with cloud providers: GitHub also announced that it is working with providers such as AWS, Google Cloud, and OpenAI to create more accurate secret detectors and respond faster to leaks.

Beyond strengthening Advanced Security and GitHub's security measures, users themselves should do some things to protect themselves from leaks.

See also: Thousands of exposed GitHub repositories are still accessible via Copilot

It is recommended to enable Push Protection at the repository, organization, or enterprise level to block secrets before they are pushed to a repository. Also, hardcoded secrets should be completely removed from the source code.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The platform also suggests using tools that integrate with CI/CD pipelines and cloud platforms to manipulate secrets programmatically, reducing human interaction that can cause errors and exposure.

The leak of 39 million secrets in 2024 is a huge issue and shows how easily sensitive information can be exposed on GitHub if users aren't careful. The fact that so many leaks were detected shows how often developers neglect basic security practices.

Unless the culture around code security changes, we will continue to see such massive leaks in the future. It's good that GitHub is upgrading Advanced Security to address these issues, but on the other hand, this massive leak highlights that security is not just a matter of tools, but also of properly educating developers.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS