github / github/roadmap

GitHub secret scanning - extended metadata is generally available [GA]

Open
#1,263 1 comment 0 reactions 0 assignees View on GitHub
cloud GitHub Advanced Security (GHAS) Shipped
Dominant language
No language data
Stars
8.9k
Forks
1.8k
PR merge metrics
No merged PRs in 30d

Description

### Value Prop
To help you understand ownership and impact of a leaked secret, GitHub secret scanning now surfaces additional metadata for supported secret types. Metadata varies by type and includes `owner-email`, `owner-id`, `owner-name`, `secret-id`, `secret name`, `secret-issued-date`, `secret-expiration-date`, `organization-name`, `organization-id`, and `last-used-date`.

### Expected Outcome
When a secret is leaked, knowing *what* was exposed is only half the battle. Teams also need to know who owns it, when it was created, and what systems it can access. This enriched metadata helps teams dramatically reduce the time it takes security and development teams to triage and remediate leaked secrets.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.