Secret scanning: `public leak` (high priority) and `multi-repo` (deduping) indicators for alerts [GA]
- 主要语言
- 没有语言数据
- 星标
- 8.9k
- 派生
- 1.8k
- PR 合并指标
- 30 天内没有已合并 PR
描述
### Value Prop
To help you triage and remediate secret leaks more effectively, GitHub secret scanning indicates if a secret detected in your repository has also leaked publicly with a `public leak` label on the alert. The alert also indicates if the secret was exposed in other repositories across your organization or enterprise with a `multi-repo` label.
### Expected Outcome
These labels provide additional understanding into the distribution of an exposed secret, while also making it easier to assess an alert’s risk and urgency. For example, a secret which has a known associated exposure in a public location has a higher likelihood of exploitation. Detection of public leaks is only currently supported for [provider-based patterns](https://docs.github.com/en/enterprise-cloud@latest/code-security/secret-scanning/introduction/supported-secret-scanning-patterns#default-patterns).
The `multi-repo` label makes it easier to de-duplicate alerts and is supported for all secret types, including [custom patterns](https://docs.github.com/en/enterprise-cloud@latest/code-security/secret-scanning/using-advanced-secret-scanning-and-push-protection-features/custom-patterns/defining-custom-patterns-for-secret-scanning). You can only view and navigate to other enterprise repositories with duplicate alerts if you have appropriate permissions to view them.
贡献指南
评估
这个 Issue 还没有评估数据。