GitHub expands security tools after 39 million secrets leaked in 2024

GitHub

GitHub announced updates to its Advanced Security platform after it detected over 39 million leaked secrets in repositories during 2024, including API keys and credentials, exposing users and organizations to serious security risks.

In a new report by GitHub, the development company says the 39 million secrets were found through its secret scanning service, a security feature that detects API keys, passwords, tokens, and other secrets in repositories. 

“Secret leaks remain one of the most common—and preventable—causes of security incidents,” reads GitHub’s announcement.

“As we develop code faster than ever previously imaginable, we’re leaking secrets faster than ever, too.”

This is happening despite GitHub’s targeted protection measures like “Push Protection,” which was introduced in April 2022 and was activated by default on all public repositories in February 2024.

According to GitHub, the main reasons why secrets continue to leak are the prioritization of convenience by developers who handle secrets during commits and accidental repository exposure through git history.

GitHub revamps Advanced Security

GitHub announced several new measures and enhancements to existing systems to mitigate secret leaks on the platform.

“As of today, our security products are available to purchase as standalone products for enterprises, enabling development teams to scale security quickly,” explained GitHub.

“Previously, investing in secret scanning and push protection required purchasing a larger suite of security tools, which made it too expensive for many organizations.

“This change ensures scalable security with Secret Protection and Code Security is no longer out of reach for many organizations.”

The GitHub Advanced Security changes are summarized as follows:

  1. Standalone Secret Protection and Code Security – Now available as separate products, these tools no longer require a full GitHub Advanced Security license, making them more affordable for smaller teams.
  2. Free organization-wide secret risk assessment – A point-in-time scan that checks all repositories (public, private, internal, and archived) for exposed secrets, free for all GitHub organizations.
  3. Push protection with delegated bypass controls – Enhanced push protection scans for secrets before code is pushed and allows organizations to define who can bypass the protection, adding policy-level control.
  4. Copilot-powered secret detection – GitHub now uses AI via Copilot to detect unstructured secrets like passwords, improving accuracy and lowering false positives.
  5. Improved detection via cloud provider partnerships – GitHub works with providers like AWS, Google Cloud, and OpenAI to build more accurate secret detectors and respond faster to leaks.

Apart from GitHub’s initiatives and improvements, users are also given a list of recommended actions to protect themselves from secret leaks.

First, it is suggested that Push Protection be enabled at the repository, organization, or enterprise level to block secrets before they’re pushed to a repository.

GitHub also highlights the importance of reducing the risk by eliminating hardcoded secrets from source code altogether, instead using environment variables, secret managers, or vaults to store them.

The platform suggests using tools that integrate with CI/CD pipelines and cloud platforms to handle secrets programmatically, reducing human interaction that can introduce errors and exposure.

Finally, GitHub users are recommended to review the ‘Best Practices‘ guide and ensure they appropriately manage secrets end-to-end.

Bill Toulas
Read More

Latest

Embracer Follows Ubisoft In Splitting Off New Publisher To Handle Huge IP, Tomb Raider & LOTR Included

Say hello to Fellowship Entertainment by Ben Kerry 11 hours ago Embracer Group has today announced plans to create a secondary publishing label called Fellowship Entertainment, in order to "capture the full potential of the high-quality assets" that the group currently owns. The Swedish game publisher says that it hopes to spin off Fellowship Entertainment

Gwyneth Paltrow’s Daughter Apple Martin in Nancy Meyers Movie

Gwyneth Paltrow's Daughter Apple Martin Makes Directorial Debut With Student Show Apple Martin doesn’t fall far from the tree. Gwyneth Paltrow and Chris Martin ’s daughter will be following in her mom’s acting footsteps and making her movie debut in Nancy Meyers’ upcoming film, Deadline and Entertainment Weekly reported on May 18. The 22-year-old—who graduated

Lil Wayne speaks out after feeling overlooked by Coachella and the Grammys

Music Lil Wayne reacts to Coachell and Grammys snub Award-winning...

Newsletter

Don't miss

Embracer Follows Ubisoft In Splitting Off New Publisher To Handle Huge IP, Tomb Raider & LOTR Included

Say hello to Fellowship Entertainment by Ben Kerry 11 hours ago Embracer Group has today announced plans to create a secondary publishing label called Fellowship Entertainment, in order to "capture the full potential of the high-quality assets" that the group currently owns. The Swedish game publisher says that it hopes to spin off Fellowship Entertainment

Gwyneth Paltrow’s Daughter Apple Martin in Nancy Meyers Movie

Gwyneth Paltrow's Daughter Apple Martin Makes Directorial Debut With Student Show Apple Martin doesn’t fall far from the tree. Gwyneth Paltrow and Chris Martin ’s daughter will be following in her mom’s acting footsteps and making her movie debut in Nancy Meyers’ upcoming film, Deadline and Entertainment Weekly reported on May 18. The 22-year-old—who graduated

Lil Wayne speaks out after feeling overlooked by Coachella and the Grammys

Music Lil Wayne reacts to Coachell and Grammys snub Award-winning...

Kehlani at 30: How ‘Folded’ Changed Everything | Billboard Women In Music 2026

MusicBillboard Women in Music 2026 Impact Award recipient...

Tesla’s Business Has Become Much More Diversified in Just the Past Five Years. Does That Make Its Stock a Better Buy Today?

Key Points Tesla's energy generation and storage segment generated 27% revenue growth last year. The company's non-automotive segments were able to help offset a double-digit decline in auto revenue in 2025. These 10 stocks could mint the next wave of millionaires › Tesla (NASDAQ: TSLA) is known for its electric vehicles (EVs), and while they

WD sees sustainability as key business driver in an ‘AI economy’

Hard drive company WD promoted long-term operations and sustainability executive Jackie Jung to become its first chief sustainability officer in February, as it steps up sales to companies building AI data centers. Her vision: Turn sustainability into a “brand” for WD, a strategy that reduces risk for the $6 billion company (formerly known as Western

5 Business Ideas Worth Starting in 2026

If there is one thing Nigerians understand well, it is how to spot opportunity inside hardship. In 2026, that mindset will matter more than ever. The economy is tough, competition is rising, and many people are looking for smarter ways to earn, build, and survive. But even in a difficult environment, some businesses still stand