github / github/roadmap

Secret scanning detects secrets in Actions logs [Public Preview]

Open
#1,282 0 comments 0 reactions 0 assignees View on GitHub
GHES 3.23 GitHub Advanced Security (GHAS) Public Preview
Dominant language
No language data
Stars
8.9k
Forks
1.8k
PR merge metrics
No merged PRs in 30d

Description

### Value Prop
Secret scanning now detects secrets exposed in GitHub Actions workflow logs, closing a common and high-risk gap in your security coverage. When a token, API key, or credential surfaces in a log, GitHub will automatically open a secret scanning alert with additional information about the finding.

### Expected Outcome
Development teams need confidence that their automation pipelines are covered alongside their source code and GitHub surfaces. By extending secret scanning to Actions logs, developers can ship faster without worrying that their pipelines are silently leaking credentials.

Contributor guide

Open the contributing guide

Research direction

This roadmap issue names no repository files, tests, or implementation entry points. Start by reviewing the secret-scanning and GitHub Actions documentation, then identify the product and engineering scope needed to detect credentials in workflow logs and create alerts with finding details.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions
Domain
devops, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.