Friday, 16 May 2025
  • My Feed
  • My Interests
  • My Saves
  • History
  • Blog
Subscribe
Capernaum
  • Finance
    • Cryptocurrency
    • Stock Market
    • Real Estate
  • Lifestyle
    • Travel
    • Fashion
    • Cook
  • Technology
    • AI
    • Data Science
    • Machine Learning
  • Health
    HealthShow More
    Eating to Keep Ulcerative Colitis in Remission 
    Eating to Keep Ulcerative Colitis in Remission 

    Plant-based diets can be 98 percent effective in keeping ulcerative colitis patients…

    By capernaum
    Foods That Disrupt Our Microbiome
    Foods That Disrupt Our Microbiome

    Eating a diet filled with animal products can disrupt our microbiome faster…

    By capernaum
    Skincare as You Age Infographic
    Skincare as You Age Infographic

    When I dove into the scientific research for my book How Not…

    By capernaum
    Treating Fatty Liver Disease with Diet 
    Treating Fatty Liver Disease with Diet 

    What are the three sources of liver fat in fatty liver disease,…

    By capernaum
    Bird Flu: Emergence, Dangers, and Preventive Measures

    In the United States in January 2025 alone, approximately 20 million commercially-raised…

    By capernaum
  • Sport
  • 🔥
  • Cryptocurrency
  • Data Science
  • Travel
  • Real Estate
  • AI
  • Technology
  • Machine Learning
  • Stock Market
  • Finance
  • Fashion
Font ResizerAa
CapernaumCapernaum
  • My Saves
  • My Interests
  • My Feed
  • History
  • Travel
  • Health
  • Technology
Search
  • Pages
    • Home
    • Blog Index
    • Contact Us
    • Search Page
    • 404 Page
  • Personalized
    • My Feed
    • My Saves
    • My Interests
    • History
  • Categories
    • Technology
    • Travel
    • Health
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Home » Blog » GitHub finds 39M reasons to upgrade security
Data Science

GitHub finds 39M reasons to upgrade security

capernaum
Last updated: 2025-04-03 12:25
capernaum
Share
GitHub finds 39M reasons to upgrade security
SHARE

GitHub finds 39M reasons to upgrade security

GitHub is beefing up its security after finding a staggering 39 million secrets—API keys, credentials, the works—leaking from repositories in 2024. This exposure puts users and organizations at serious risk.

According to GitHub’s report, this massive leak was detected by its secret scanning service, which identifies exposed API keys, passwords, and tokens within repositories.

“Secret leaks remain one of the most common—and preventable—causes of security incidents,” GitHub stated in its announcement, noting, “As we develop code faster than ever previously imaginable, we’re leaking secrets faster than ever, too.”

Despite measures like “Push Protection,” launched in April 2022 and enabled by default on public repositories in February 2024, secrets continue to leak due to developers prioritizing convenience when handling secrets during commits and accidental repository exposure through git history.

To combat these leaks, GitHub is rolling out several new measures and enhancements:

  • Standalone secret protection and code security: Available as separate products, these tools no longer require a full GitHub Advanced Security license, aiming to be more affordable for smaller teams.
  • Free organization-wide secret risk assessment: Checks all repositories (public, private, internal, and archived) for exposed secrets, available to all GitHub organizations at no cost.
  • Push protection with delegated bypass controls: Enhanced push protection scans for secrets before code is pushed and allows organizations to define who can bypass the protection, thus adding policy-level control.
  • Copilot-powered secret detection: GitHub is leveraging AI via Copilot to detect unstructured secrets like passwords, aiming to improve accuracy and lower false positives.
  • Improved detection via cloud provider partnerships: GitHub is collaborating with providers such as AWS, Google Cloud, and OpenAI to enhance the accuracy of secret detectors and speed up responses to leaks.

“As of today, our security products are available to purchase as standalone products for enterprises, enabling development teams to scale security quickly,” GitHub explained. “Previously, investing in secret scanning and push protection required purchasing a larger suite of security tools, which made it too expensive for many organizations.”


Court dismisses billion-dollar claims against GitHub Copilot


Beyond GitHub’s upgrades, users are urged to take proactive steps to safeguard against secret leaks. Recommendations include enabling Push Protection at the repository, organization, or enterprise level to preemptively block secrets. GitHub also suggests eliminating hardcoded secrets by using environment variables, secret managers, or vaults.

The platform further advises using tools integrated with CI/CD pipelines and cloud platforms for programmatic secret handling, minimizing error-prone human interaction and potential exposure.

Lastly, GitHub encourages users to review the ‘Best Practices’ guide for comprehensive secrets management.


Featured image credit

Share This Article
Twitter Email Copy Link Print
Previous Article OpenAI’s o3 costs way, way more than you think OpenAI’s o3 costs way, way more than you think
Next Article Microsoft’s Bing AI search mode is lurking Microsoft’s Bing AI search mode is lurking
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Using RSS feeds, we aggregate news from trusted sources to ensure real-time updates on the latest events and trends. Stay ahead with timely, curated information designed to keep you informed and engaged.
TwitterFollow
TelegramFollow
LinkedInFollow
- Advertisement -
Ad imageAd image

You Might Also Like

Infrastructure automation

By capernaum

OEM (original equipment manufacturer)

By capernaum

Google Drive

By capernaum

Advanced analytics

By capernaum
Capernaum
Facebook Twitter Youtube Rss Medium

Capernaum :  Your instant connection to breaking news & stories . Stay informed with real-time coverage across  AI ,Data Science , Finance, Fashion , Travel, Health. Your trusted source for 24/7 insights and updates.

© Capernaum 2024. All Rights Reserved.

CapernaumCapernaum
Welcome Back!

Sign in to your account

Lost your password?