GitLab
Security & compliance
Code quality
Secret push protection disabled
Part of the GitLab project protection check · fix arrives as a guide
What it is
Secret push protection is disabled, so a push containing a recognised credential is not rejected.
Why it matters
It is the only control that stops a secret before it exists in history. Once pushed, the credential must be rotated regardless of what happens to the commit.
How to fix it
Enable "Prevent committing secrets to Git" under Settings → Repository → Push rules (GitLab Premium and above), ideally on the owning group so new projects inherit it.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.