github / github/roadmap

Secret scanning detects secrets in Actions logs [Public Preview]

Abierto
#1,282 0 comentarios 0 reacciones 0 asignados Ver en GitHub
GHES 3.23 GitHub Advanced Security (GHAS) Public Preview
Lenguaje dominante
Sin datos de lenguaje
Estrellas
8.9k
Forks
1.8k
Métricas de merge de PR
Sin PR fusionados en 30 d

Descripción

### Value Prop
Secret scanning now detects secrets exposed in GitHub Actions workflow logs, closing a common and high-risk gap in your security coverage. When a token, API key, or credential surfaces in a log, GitHub will automatically open a secret scanning alert with additional information about the finding.

### Expected Outcome
Development teams need confidence that their automation pipelines are covered alongside their source code and GitHub surfaces. By extending secret scanning to Actions logs, developers can ship faster without worrying that their pipelines are silently leaking credentials.

Guía de contribución

Abrir la guía de contribución

Línea de trabajo

This roadmap issue names no repository files, tests, or implementation entry points. Start by reviewing the secret-scanning and GitHub Actions documentation, then identify the product and engineering scope needed to detect credentials in workflow logs and create alerts with finding details.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
github-actions
Área
devops, security
Tipo de issue
Nueva funcionalidad
Dificultad
5/5
Tiempo estimado
Más de una semana
Estado de actividad
Tranquilo
Claridad
Necesita aclaración
Aptitud para principiantes
20/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.