Learn about secret scanning patterns, risk report CSV contents, and GitHub secrets.
Learn about the usage, scope, and access permissions for GitHub secrets.
Lists of supported secrets and the partners that GitHub works with to prevent fraudulent use of secrets that were committed accidentally.
Secret scanning uses pattern matching and validation to detect secrets. Detection varies based on pattern pairs, token types, and push protection settings.
Use specific regular expression syntax to define accurate custom patterns for secret scanning.
Understand the data included in the CSV export of the secret risk assessment report.
Understand the data displayed in the secret scanning pattern configuration page to make informed decisions about push protection settings.
All GitHub docs are open source. See something that's wrong or unclear? Submit a pull request.
Make a contribution