GitHub
Security & compliance
Code quality
Secret-scanning push protection disabled
Part of the Repository protection posture check · fix arrives as a guide
What it is
Secret-scanning push protection is disabled, so a commit containing a recognised credential is not blocked at push time.
Why it matters
Push protection is the only control that stops a secret before it enters history. Once it is pushed the credential must be treated as compromised and rotated, whatever you do to the commit afterwards.
How to fix it
Enable secret scanning and push protection in the repository security settings, ideally at the organisation level so new repositories inherit it.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.