github / roadmap

GitHub public roadmap
Creative Commons Attribution 4.0 International
7.9k stars 989 forks source link

Secret scanning detects secrets in GitHub wikis #964

Open github-product-roadmap opened 4 months ago

github-product-roadmap commented 4 months ago

Summary

Secret scanning is expanding detection coverage beyond commit content. GitHub now detects secrets found in GitHub wiki content.

As GitHub expands support, GitHub will be performing backfills to detect historically existing secrets across your GitHub wikis.

This release follows recent releases, including support of secret scanning for GitHub issues, pull requests, and discussions.

Intended Outcome

Secrets can be exposed anywhere -- not just across code content. GitHub helps keep you safe by automatically scanning additional surfaces across GitHub, without the need for any additional setup.

How will it work?

For repositories where secret scanning is enabled, you'll automatically begin to receive secret scanning alerts for any exposed secrets in pull requests or discussions. GitHub will also continue to scan public repositories for publicly leaked secrets, and will now notify partners in secret scanning's partnership program if secrets are detected in public pull requests or discussions.