GitLab Security & compliance Code quality

Secret push protection disabled

Part of the GitLab project protection check · fix arrives as a guide

What it is

Secret push protection is disabled, so a push containing a recognised credential is not rejected.

Why it matters

It is the only control that stops a secret before it exists in history. Once pushed, the credential must be rotated regardless of what happens to the commit.

How to fix it

Enable "Prevent committing secrets to Git" under Settings → Repository → Push rules (GitLab Premium and above), ideally on the owning group so new projects inherit it.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.