github / github/roadmap

Public Monitoring For Enterprises [General Availability]

Đang mở
#1,315 0 bình luận 0 reaction 0 người được giao Xem trên GitHub
cloud GA GitHub Advanced Security (GHAS)
Ngôn ngữ chính
Không có dữ liệu ngôn ngữ
Star
8.9k
Fork
1.8k
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Mô tả

### Value Prop

Secrets don’t respect boundaries; scanning for them shouldn’t either.

GitHub monitors the entire public surface of github.com for leaked secrets in real time. Public monitoring attributes those secrets back to your enterprise, based on where your people commit.

### Expected Outcome

Secret scanning has always protected the repositories you own. But secrets leak beyond that boundary. For example, a developer commits to a personal fork or an open source project, or they paste a token into a public issue or pull request, and this often happens from an account your security team isn’t tracking. Exposures like these were nearly impossible to find and often only surfaced after they’d been abused by bad actors.

Public monitoring closes that gap. It finds these vulnerabilities and attributes them to your enterprise so you can respond quickly. The feature scans for secrets exposed anywhere in public content across github.com—including git content, pull request comments, and GitHub issues—and natively attributes each one back to your enterprise, through GitHub’s identity layer and verified domains.

Because the activity happens on GitHub, so does the attribution: in real time (not a nightly async crawl), definitively with native platform metadata (not on a guess from a commit email), and across arbitrary public repositories (not just surfaces where you tell us to look).

Public monitoring will never scan private repositories; it surfaces only secrets that are already exposed publicly, so you can revoke leaked secrets before they’re abused by bad actors. The feature is available at no additional cost for enterprises with GitHub Secret Protection.

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Hướng nghiên cứu

This roadmap issue describes public monitoring for GitHub Secret Protection but names no implementation files, tests, or entry points. Start by identifying the repository and existing secret-scanning components involved; the work is done when public GitHub content is scanned in real time and exposed secrets are attributed to the correct enterprise.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
github
Lĩnh vực
security
Loại issue
Tính năng
Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức độ hoạt động
Ít trao đổi
Độ rõ ràng
Cần làm rõ
Mức phù hợp với người mới
25/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.