GitHub
Security & compliance
Active leaked secret (secret scanning)
Part of the Supply-chain alerts check · fix arrives as a guide
What it is
GitHub secret scanning has detected an active credential in the repository.
Why it matters
The provider has confirmed the pattern and, for partner-scanned types, that the credential is still live. It is in history and readable by anyone with access — this is an incident, not a backlog item.
How to fix it
Rotate the credential first, then remove it from the code. Check the provider's audit log for use you did not authorise, and enable push protection so the next one is blocked before it lands.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.