GitHub expands security tools after 39 million secrets leaked in 2024

GitHub

GitHub announced updates to its Advanced Security platform after it detected over 39 million leaked secrets in repositories during 2024, including API keys and credentials, exposing users and organizations to serious security risks.

In a new report by GitHub, the development company says the 39 million secrets were found through its secret scanning service, a security feature that detects API keys, passwords, tokens, and other secrets in repositories. 

“Secret leaks remain one of the most common—and preventable—causes of security incidents,” reads GitHub’s announcement.

“As we develop code faster than ever previously imaginable, we’re leaking secrets faster than ever, too.”

This is happening despite GitHub’s targeted protection measures like “Push Protection,” which was introduced in April 2022 and was activated by default on all public repositories in February 2024.

According to GitHub, the main reasons why secrets continue to leak are the prioritization of convenience by developers who handle secrets during commits and accidental repository exposure through git history.

GitHub revamps Advanced Security

GitHub announced several new measures and enhancements to existing systems to mitigate secret leaks on the platform.

“As of today, our security products are available to purchase as standalone products for enterprises, enabling development teams to scale security quickly,” explained GitHub.

“Previously, investing in secret scanning and push protection required purchasing a larger suite of security tools, which made it too expensive for many organizations.

“This change ensures scalable security with Secret Protection and Code Security is no longer out of reach for many organizations.”

The GitHub Advanced Security changes are summarized as follows:

  1. Standalone Secret Protection and Code Security – Now available as separate products, these tools no longer require a full GitHub Advanced Security license, making them more affordable for smaller teams.
  2. Free organization-wide secret risk assessment – A point-in-time scan that checks all repositories (public, private, internal, and archived) for exposed secrets, free for all GitHub organizations.
  3. Push protection with delegated bypass controls – Enhanced push protection scans for secrets before code is pushed and allows organizations to define who can bypass the protection, adding policy-level control.
  4. Copilot-powered secret detection – GitHub now uses AI via Copilot to detect unstructured secrets like passwords, improving accuracy and lowering false positives.
  5. Improved detection via cloud provider partnerships – GitHub works with providers like AWS, Google Cloud, and OpenAI to build more accurate secret detectors and respond faster to leaks.

Apart from GitHub’s initiatives and improvements, users are also given a list of recommended actions to protect themselves from secret leaks.

First, it is suggested that Push Protection be enabled at the repository, organization, or enterprise level to block secrets before they’re pushed to a repository.

GitHub also highlights the importance of reducing the risk by eliminating hardcoded secrets from source code altogether, instead using environment variables, secret managers, or vaults to store them.

The platform suggests using tools that integrate with CI/CD pipelines and cloud platforms to handle secrets programmatically, reducing human interaction that can introduce errors and exposure.

Finally, GitHub users are recommended to review the ‘Best Practices‘ guide and ensure they appropriately manage secrets end-to-end.

Bill Toulas
Read More

Latest

‘Godzilla’ Studio Toho Acquires U.K.’s Anime Limited, Forms European HQ in London

Japanese entertainment giant Toho has acquired U.K.-based distributor Anime Limited from Germany’s Plaion Pictures, marking a major expansion of the “Godzilla” studio’s European operations. The deal sees Toho Global – the company’s consolidated overseas subsidiary – take full ownership of Glasgow-based Anime Limited, which will operate as a standalone subsidiary. Financial terms were not disclosed.

Exodus Studio Head Steps Down Just After Major Trailer Drop At The Game Awards

GameSpot may receive revenue from affiliate and advertising partnerships for sharing this content and from purchases through links. James Ohlen, the Bioware veteran who led development on upcoming sci-fi RPG Exodus, has stepped down from his position as the head of Archetype Entertainment. Ohlen's exit comes just after the studio debuted a flashy new trailer

Bandai Namco sells Limbic Entertainment to “private investor”

Its current leadership will remain, as will the company's name and identity Bandai Namco is selling Limbic Entertainment to "a private investor specializing in video games." The Japanese megacorp says the sale of Limbic, a wholly-owned subsidiary of Bandai Namco, forms part of its strategy "to refocus its portfolio to areas where the company delivers

Newsletter

Don't miss

‘Godzilla’ Studio Toho Acquires U.K.’s Anime Limited, Forms European HQ in London

Japanese entertainment giant Toho has acquired U.K.-based distributor Anime Limited from Germany’s Plaion Pictures, marking a major expansion of the “Godzilla” studio’s European operations. The deal sees Toho Global – the company’s consolidated overseas subsidiary – take full ownership of Glasgow-based Anime Limited, which will operate as a standalone subsidiary. Financial terms were not disclosed.

Exodus Studio Head Steps Down Just After Major Trailer Drop At The Game Awards

GameSpot may receive revenue from affiliate and advertising partnerships for sharing this content and from purchases through links. James Ohlen, the Bioware veteran who led development on upcoming sci-fi RPG Exodus, has stepped down from his position as the head of Archetype Entertainment. Ohlen's exit comes just after the studio debuted a flashy new trailer

Bandai Namco sells Limbic Entertainment to “private investor”

Its current leadership will remain, as will the company's name and identity Bandai Namco is selling Limbic Entertainment to "a private investor specializing in video games." The Japanese megacorp says the sale of Limbic, a wholly-owned subsidiary of Bandai Namco, forms part of its strategy "to refocus its portfolio to areas where the company delivers

Enso: AI-powered Business Automation Platform

Enso is an AI-powered business automation platform designed to streamline various business operations, including marketing, sales, and administrative tasks. By leveraging a suite of over 100 AI agents, Enso aims to enhance efficiency and productivity for small businesses. Key Features Comprehensive AI Agents: Enso offers a diverse range of AI tools that assist with content

Small Business In Spotlight Next Month | Mirage News

October is prime time for small businesses to shine, with Camden Council gearing up to celebrate Small Business Month. This year's program offers a lineup of workshops, webinars and networking opportunities led by industry experts and small business professionals. It includes: AI-Powered Search Engine Optimisation, an online webinar unpacking the rise of Generative Engine Optimisation

Globacom at 22: A business beyond profit – Celebrating Adenuga, the visionary icon who redefined Africa’s enterprise landscape by Louis Ibe

Twenty-two years ago, on 29 August 2003, Nigeria’s telecommunications landscape changed forever. A bold new entrant called Globacom emerged, not just to compete for market share, but to democratise access to communication, redefine service delivery, and make technology an empowering force for the people. From the moment it introduced per-second billing — a feat that