Home / Companies / Socket / Blog / Post Details
Content Deep Dive

GitHub Activates Push Protection by Default After Detecting ...

Blog post from Socket

Post Details
Company
Date Published
Author
Sarah Gooding
Word Count
668
Company Posts That Month
42
Language
English
Hacker News Points
-
Post removed?
No
Summary

GitHub has activated push protection by default for all user accounts to combat the significant issue of leaked secrets, such as API keys and tokens, in open source development, which can lead to severe security breaches. The platform had detected over one million leaked secrets in public repositories within the first eight weeks of 2024, highlighting the scale of the problem. TruffleHog, a secrets scanning tool, found that 74% of leaked keys remained valid 31 days after exposure, indicating a misunderstanding among developers about the need to rotate credentials. Previous high-profile breaches, such as those involving Toyota and Mercedes-Benz, have underscored the risks associated with exposed credentials. Initially introduced as an optional feature, push protection now blocks commits containing secrets and provides organizations with data on intercepted secrets, although it can be bypassed or disabled by users in specific situations. GitHub's secret scanning supports over 200 token types from more than 180 service providers, and making push protection a default feature represents a significant step in reducing the availability of leaked secrets to malicious actors.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 16 1,488 268 99 +7%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.