github / github/roadmap

Public Monitoring For Enterprises [General Availability]

オープン
#1,315 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
cloud GA GitHub Advanced Security (GHAS)
主要言語
言語のデータがありません
スター
8.9k
フォーク
1.8k
PR マージ指標
30日以内にマージされた PR はありません

説明

### Value Prop

Secrets don’t respect boundaries; scanning for them shouldn’t either.

GitHub monitors the entire public surface of github.com for leaked secrets in real time. Public monitoring attributes those secrets back to your enterprise, based on where your people commit.

### Expected Outcome

Secret scanning has always protected the repositories you own. But secrets leak beyond that boundary. For example, a developer commits to a personal fork or an open source project, or they paste a token into a public issue or pull request, and this often happens from an account your security team isn’t tracking. Exposures like these were nearly impossible to find and often only surfaced after they’d been abused by bad actors.

Public monitoring closes that gap. It finds these vulnerabilities and attributes them to your enterprise so you can respond quickly. The feature scans for secrets exposed anywhere in public content across github.com—including git content, pull request comments, and GitHub issues—and natively attributes each one back to your enterprise, through GitHub’s identity layer and verified domains.

Because the activity happens on GitHub, so does the attribution: in real time (not a nightly async crawl), definitively with native platform metadata (not on a guess from a commit email), and across arbitrary public repositories (not just surfaces where you tell us to look).

Public monitoring will never scan private repositories; it surfaces only secrets that are already exposed publicly, so you can revoke leaked secrets before they’re abused by bad actors. The feature is available at no additional cost for enterprises with GitHub Secret Protection.

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

このロードマップ issue は GitHub Secret Protection の公開モニタリングについて説明していますが、実装ファイル、テスト、エントリーポイントを指定していません。まず、関係するリポジトリと既存の secret-scanning コンポーネントを特定してください。公開 GitHub コンテンツがリアルタイムでスキャンされ、露出した secret が正しい enterprise に帰属されれば、作業は完了です。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
github
領域
security
issue の種類
機能追加
難易度
5/5
見積もり時間
1週間以上
活発さ
静か
明瞭さ
説明が足りない
初心者へのやさしさ
25/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。