GitHub

GitHub’s Secret Scanning Now Includes Validity Checks for Major Token Providers

Enhanced Security: GitHub Expands Secret Scanning to Verify Token Validity

Since the beginning of 2023, GitHub has made secret scanning and secret scanning push protection available at no cost for users of public repositories, demonstrating its commitment to supporting open source users.

Users with eligible accounts can activate secret scanning, which now encompasses a wider range of third-party services, by navigating to Settings > Code security and analysis > Secret scanning. Within these settings, users can enable the “Automatically verify if a secret is valid by sending it to the relevant partner” option.