Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Secret scanning: public leak (high priority) and multi-repo (deduping) indicators for alerts [GA] #1040

Open
glider-bot opened this issue Nov 20, 2024 · 0 comments
Labels
ga Feature phase: Generally available GHES 3.16 GHES 3.16 GitHub Advanced Security (GHAS) Product SKU: GitHub Advanced Security

Comments

@glider-bot
Copy link
Collaborator

Value Prop

To help you triage and remediate secret leaks more effectively, GitHub secret scanning indicates if a secret detected in your repository has also leaked publicly with a public leak label on the alert. The alert also indicates if the secret was exposed in other repositories across your organization or enterprise with a multi-repo label.

Expected Outcome

These labels provide additional understanding into the distribution of an exposed secret, while also making it easier to assess an alert’s risk and urgency. For example, a secret which has a known associated exposure in a public location has a higher likelihood of exploitation. Detection of public leaks is only currently supported for provider-based patterns.

The multi-repo label makes it easier to de-duplicate alerts and is supported for all secret types, including custom patterns. You can only view and navigate to other enterprise repositories with duplicate alerts if you have appropriate permissions to view them.

@glider-bot glider-bot added ga Feature phase: Generally available GHES 3.16 GHES 3.16 GitHub Advanced Security (GHAS) Product SKU: GitHub Advanced Security labels Nov 20, 2024
@glider-bot glider-bot moved this to Q1 2025 – Jan-Mar in GitHub Public Roadmap Nov 20, 2024
@github github locked and limited conversation to collaborators Nov 21, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
ga Feature phase: Generally available GHES 3.16 GHES 3.16 GitHub Advanced Security (GHAS) Product SKU: GitHub Advanced Security
Projects
Status: Q1 2025 – Jan-Mar
Development

No branches or pull requests

1 participant