GitHub Secrets Leaks

The cluster revolves around discussions of accidentally committing secrets, credentials, and keys to GitHub repositories, the risks of exposure in public and private repos, GitHub's secret scanning features, and tools for detection and prevention.

➡️ Stable 0.5x Security
4,368
Comments
20
Years Active
5
Top Authors
#4171
Topic ID

Activity Over Time

2007
1
2008
2
2009
8
2010
40
2011
28
2012
140
2013
224
2014
164
2015
274
2016
179
2017
329
2018
198
2019
265
2020
283
2021
375
2022
533
2023
458
2024
356
2025
473
2026
38

Keywords

e.g CLI carlchenet.com SECURITY.md SSH EDIT bit.ly GH HN passwords.txt github secrets credentials repo repos private public git repository keys

Sample Comments

azinman2 Jul 17, 2021 View on HN

I doubt ppl would want to give github all their actual secrets

TwelveNights Aug 24, 2020 View on HN

Any credentials that are pushed to GitHub are as good as immediately compromised.

toomuchtodo Jun 2, 2020 View on HN

Github monitors for public commits of service secrets. Not an excuse to commit secrets, but there is a bit of a safety net.> When you push to a public repository, GitHub scans the content of the commits for secrets. If you switch a private repository to public, GitHub scans the entire repository for secrets.> When secret scanning detects a set of credentials, we notify the service provider who issued the secret. The service provider validates the credential and then decides whether t

lumberjack24 Aug 10, 2021 View on HN

Try GitGuardian to monitor internal repos on GitHub, 100k+ developers use it to scan their commits for all sorts of credentials and secrets.https://bit.ly/3AHfI9d

drran Nov 13, 2021 View on HN

GitHub can alter the CODE. Why it should play with just a key? If GitHub wants to pwn the whole world, it can do it right now.

moffkalast Jul 5, 2023 View on HN

Ah yes, giving your github credentials to a smart black box. What could possibly go wrong.

gbtw Jul 3, 2021 View on HN

Does github guarantee that my private repo's content are not being leaked this way in the future?

mkozlows Dec 30, 2025 View on HN

If your secrets are in your repo, you've probably already leaked them.

carlchenet Jan 7, 2018 View on HN

I wrote "The Github Threat" about this possible issue https://carlchenet.com/the-github-threat/

Dowwie Jan 15, 2023 View on HN

You're giving Github way too much unearned credit about its security practices