Secret scanning detects secrets in Actions logs [Public Preview]
- Ngôn ngữ chính
- Không có dữ liệu ngôn ngữ
- Star
- 8.9k
- Fork
- 1.8k
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Mô tả
### Value Prop
Secret scanning now detects secrets exposed in GitHub Actions workflow logs, closing a common and high-risk gap in your security coverage. When a token, API key, or credential surfaces in a log, GitHub will automatically open a secret scanning alert with additional information about the finding.
### Expected Outcome
Development teams need confidence that their automation pipelines are covered alongside their source code and GitHub surfaces. By extending secret scanning to Actions logs, developers can ship faster without worrying that their pipelines are silently leaking credentials.
Hướng dẫn đóng góp
Hướng nghiên cứu
This roadmap issue names no repository files, tests, or implementation entry points. Start by reviewing the secret-scanning and GitHub Actions documentation, then identify the product and engineering scope needed to detect credentials in workflow logs and create alerts with finding details.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Đánh giá
- Công nghệ
- github-actions
- Lĩnh vực
- devops, security
- Loại issue
- Tính năng
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức độ hoạt động
- Ít trao đổi
- Độ rõ ràng
- Cần làm rõ
- Mức phù hợp với người mới
- 20/100