github / github/roadmap

Secret scanning detects secrets in Actions logs [Public Preview]

Offen
#1,282 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
GHES 3.23 GitHub Advanced Security (GHAS) Public Preview
Vorherrschende Sprache
Keine Sprachdaten
Sterne
8.9k
Forks
1.8k
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

### Value Prop
Secret scanning now detects secrets exposed in GitHub Actions workflow logs, closing a common and high-risk gap in your security coverage. When a token, API key, or credential surfaces in a log, GitHub will automatically open a secret scanning alert with additional information about the finding.

### Expected Outcome
Development teams need confidence that their automation pipelines are covered alongside their source code and GitHub surfaces. By extending secret scanning to Actions logs, developers can ship faster without worrying that their pipelines are silently leaking credentials.

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

This roadmap issue names no repository files, tests, or implementation entry points. Start by reviewing the secret-scanning and GitHub Actions documentation, then identify the product and engineering scope needed to detect credentials in workflow logs and create alerts with finding details.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
github-actions
Bereich
devops, security
Issue-Typ
Feature
Schwierigkeit
5/5
Geschätzter Aufwand
Über eine Woche
Aktivitätsstatus
Ruhig
Klarheit
Muss geklärt werden
Anfängerfreundlichkeit
20/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.