GitHub Security & compliance Code quality

Secret-scanning push protection disabled

Part of the Repository protection posture check · fix arrives as a guide

What it is

Secret-scanning push protection is disabled, so a commit containing a recognised credential is not blocked at push time.

Why it matters

Push protection is the only control that stops a secret before it enters history. Once it is pushed the credential must be treated as compromised and rotated, whatever you do to the commit afterwards.

How to fix it

Enable secret scanning and push protection in the repository security settings, ideally at the organisation level so new repositories inherit it.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.