github / github/roadmap

Public Monitoring For Enterprises [General Availability]

Ouverte
#1,315 0 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
cloud GA GitHub Advanced Security (GHAS)
Langage dominant
Aucune donnée de langage
Étoiles
8.9k
Forks
1.8k
Métriques de merge des PR
Aucune PR mergée en 30 j

Description

### Value Prop

Secrets don’t respect boundaries; scanning for them shouldn’t either.

GitHub monitors the entire public surface of github.com for leaked secrets in real time. Public monitoring attributes those secrets back to your enterprise, based on where your people commit.

### Expected Outcome

Secret scanning has always protected the repositories you own. But secrets leak beyond that boundary. For example, a developer commits to a personal fork or an open source project, or they paste a token into a public issue or pull request, and this often happens from an account your security team isn’t tracking. Exposures like these were nearly impossible to find and often only surfaced after they’d been abused by bad actors.

Public monitoring closes that gap. It finds these vulnerabilities and attributes them to your enterprise so you can respond quickly. The feature scans for secrets exposed anywhere in public content across github.com—including git content, pull request comments, and GitHub issues—and natively attributes each one back to your enterprise, through GitHub’s identity layer and verified domains.

Because the activity happens on GitHub, so does the attribution: in real time (not a nightly async crawl), definitively with native platform metadata (not on a guess from a commit email), and across arbitrary public repositories (not just surfaces where you tell us to look).

Public monitoring will never scan private repositories; it surfaces only secrets that are already exposed publicly, so you can revoke leaked secrets before they’re abused by bad actors. The feature is available at no additional cost for enterprises with GitHub Secret Protection.

Guide de contribution

Ouvrir le guide de contribution

Piste de recherche

This roadmap issue describes public monitoring for GitHub Secret Protection but names no implementation files, tests, or entry points. Start by identifying the repository and existing secret-scanning components involved; the work is done when public GitHub content is scanned in real time and exposed secrets are attributed to the correct enterprise.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
github
Domaine
security
Type d'issue
Fonctionnalité
Difficulté
5/5
Temps estimé
Plus d'une semaine
Activité
Calme
Clarté
À clarifier
Accessibilité débutants
25/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.