CuraDevOps

tag: Secret-Scanning · 4 items

2026-08-09 · GitHub Changelog · source ↗ #secret-scanning#github#supply-chain
  • Platform/SRE — Skip
  • CI/CD — Learn: GitHub expanded push protection to block additional secret types and added a new scanning partner; worth reviewing if your pipelines commit credentials that may now be flagged before merge.
  • Leader — Skip
2026-07-16 · GitHub Changelog · source ↗ #secret-scanning#supply-chain#github
  • Platform/SRE — Skip
  • CI/CD — Plan: New secret types are now auto-detected in repo scans; review your secret scanning policy to ensure newly covered credential types (Resend, APIclub) are included in alerting and rotation workflows.
  • Leader — Skip
  • Platform/SRE — Skip
  • CI/CD — Plan: New GA endpoints let teams manage secret scanning custom patterns as code, enabling IaC-style enforcement of scanning policies across repos; schedule adoption as part of supply-chain hardening this quarter.
  • Leader — Skip
  • Signals: GA announcement
2026-07-11 · GitHub Changelog · source ↗ #secret-scanning#github#security
  • Platform/SRE — Skip
  • CI/CD — Learn: If your pipelines parse or display GitHub secret scanning output, the renamed detector type labels may affect dashboards or tooling that filters by those names — low urgency, no deadline.
  • Leader — Skip