github / github/roadmap

Public Monitoring For Enterprises [General Availability]

Aperta
#1,315 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
cloud GA GitHub Advanced Security (GHAS)
Lingua principale
Nessun dato sulla lingua
Stelle
8.9k
Fork
1.8k
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Descrizione

### Value Prop

Secrets don’t respect boundaries; scanning for them shouldn’t either.

GitHub monitors the entire public surface of github.com for leaked secrets in real time. Public monitoring attributes those secrets back to your enterprise, based on where your people commit.

### Expected Outcome

Secret scanning has always protected the repositories you own. But secrets leak beyond that boundary. For example, a developer commits to a personal fork or an open source project, or they paste a token into a public issue or pull request, and this often happens from an account your security team isn’t tracking. Exposures like these were nearly impossible to find and often only surfaced after they’d been abused by bad actors.

Public monitoring closes that gap. It finds these vulnerabilities and attributes them to your enterprise so you can respond quickly. The feature scans for secrets exposed anywhere in public content across github.com—including git content, pull request comments, and GitHub issues—and natively attributes each one back to your enterprise, through GitHub’s identity layer and verified domains.

Because the activity happens on GitHub, so does the attribution: in real time (not a nightly async crawl), definitively with native platform metadata (not on a guess from a commit email), and across arbitrary public repositories (not just surfaces where you tell us to look).

Public monitoring will never scan private repositories; it surfaces only secrets that are already exposed publicly, so you can revoke leaked secrets before they’re abused by bad actors. The feature is available at no additional cost for enterprises with GitHub Secret Protection.

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

This roadmap issue describes public monitoring for GitHub Secret Protection but names no implementation files, tests, or entry points. Start by identifying the repository and existing secret-scanning components involved; the work is done when public GitHub content is scanned in real time and exposed secrets are attributed to the correct enterprise.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
github
Ambito
security
Tipo di issue
Funzionalità
Difficoltà
5/5
Tempo stimato
Più di una settimana
Stato di attività
Tranquilla
Chiarezza
Da chiarire
Idoneità per principianti
25/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.