Home / Companies / GitHub / Blog / Post Details
Content Deep Dive

How GitHub used secret scanning to reach inbox zero

Blog post from GitHub

Post Details
Company
Date Published
Author
Michael Recachinas
Word Count
1,991
Company Posts That Month
21
Language
English
Hacker News Points
-
Post removed?
No
Summary

GitHub Security initiated a comprehensive effort to improve secrets hygiene across its repositories, uncovering over 20,000 alerts in the process. The team found that most alerts were not high-risk, with only five repositories accounting for the bulk of inactive secrets. Through a phased approach, they implemented secret scanning and push protection to prevent new issues, triaged existing alerts, validated the status of credentials, established ownership for secrets, and automated workflows to manage alerts efficiently. The initiative emphasized the importance of durable ownership and systematizing processes to ensure accountability and ongoing security improvements. This effort reflects GitHub's commitment to maintaining high security standards and serves as a model for others to enhance their secrets management practices.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 24 2,588 483 133 +2%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.