GitHub has implemented the ability to proactively block API token leaks

GitHub has announced enhanced protection against the accidental inclusion of confidential data in repositories left by developers in the code. For example, configuration files containing database passwords, tokens, or API access keys sometimes end up in a repository. Previously, scanning was performed in passive mode, which allowed for the detection of leaks that had already occurred in the repository. To prevent leaks, GitHub has additionally started offering the option to automatically block commits that contain confidential data.

The check is performed when executing git push and leads to the generation of a security warning if API connection tokens are found in the code. A total of 69 templates have been implemented to detect various types of keys, tokens, certificates, and credentials. To avoid false positives, only guaranteed identifiable types of tokens are checked. After a block, the developer is prompted to review the problematic code, fix the leak, and repeat the commit, or mark the block as false.

The option for proactive leak blocking is currently available only to organizations with access to the 'GitHub Advanced Security' service. Passive scanning is free for all public repositories but remains paid for private repositories. It is reported that passive scanning has already detected over 700,000 leaks of confidential data in private repositories.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster