github / github/roadmap

Secret scanning: `public leak` (high priority) and `multi-repo` (deduping) indicators for alerts [GA]

オープン
#1,040 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
Enterprise Free GA GitHub Advanced Security (GHAS) Shipped
主要言語
言語のデータがありません
スター
8.9k
フォーク
1.8k
PR マージ指標
30日以内にマージされた PR はありません

説明

### Value Prop

To help you triage and remediate secret leaks more effectively, GitHub secret scanning indicates if a secret detected in your repository has also leaked publicly with a `public leak` label on the alert. The alert also indicates if the secret was exposed in other repositories across your organization or enterprise with a `multi-repo` label.

### Expected Outcome

These labels provide additional understanding into the distribution of an exposed secret, while also making it easier to assess an alert’s risk and urgency. For example, a secret which has a known associated exposure in a public location has a higher likelihood of exploitation. Detection of public leaks is only currently supported for [provider-based patterns](https://docs.github.com/en/enterprise-cloud@latest/code-security/secret-scanning/introduction/supported-secret-scanning-patterns#default-patterns).

The `multi-repo` label makes it easier to de-duplicate alerts and is supported for all secret types, including [custom patterns](https://docs.github.com/en/enterprise-cloud@latest/code-security/secret-scanning/using-advanced-secret-scanning-and-push-protection-features/custom-patterns/defining-custom-patterns-for-secret-scanning). You can only view and navigate to other enterprise repositories with duplicate alerts if you have appropriate permissions to view them.

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。