AI觉醒星球
Awakening is here
Knowledge File / 全球热点解读
2026-07-16 6 浏览 公开

秘密扫描与公共监控的改进

GitHub本周推出了秘密扫描和公共监控的多项改进,包括新增合作伙伴Resend、新秘密类型检测、默认阻止火山引擎秘密、webhook增加字段、公共监控警报列表增加洞察卡片等。

SOURCE / 全球热点解读 MIN / 9 ACCESS / 公开 POST / 2026-07-16 06:38:16

原贴

查看原文
作者:Allison 来源站点:github.blog 原贴时间:

原文

This week, we’re rolling out several improvements to secret scanning and public monitoring: Resend is now a GitHub secret scanning partner. Secret scanning now detects new secret types from APIclub and Resend. Secret scanning now blocks VolcEngine secrets with push protection by default. The secret_scanning_alert webhook now includes a secret_category field (i.e., default or generic ) so you can distinguish between specific and generic types. The public monitoring alert list now surfaces insight cards at the top of the page, including a breakdown of associated leaks by attribution, your enterprise member count, and your verified domains. GitHub secret scanning protects users by searching repositories for known types of secrets such as tokens and private keys. By identifying and flagging these secrets, our scans help prevent data leaks and fraud. We have partnered with Resend to scan for their tokens to help secure the development community. GitHub will forward any exposed secrets found in public repositories to Resend, who will take appropriate action, including revoking the secret or notifying respect admins. Learn more about the secret scanning partnership program . If you are a secret issuer interested in partnering with us, you can get started by opening a ticket with GitHub support . Secret scanning now automatically detects the following new secret types in your repositories. Partner secrets are automatically reported to the secret issuer when found in public repositories through the secret scanning partnership program . User secrets generate secret scanning alerts when found in public or private repositories. The following detector is now included in push protection by default. Repositories with secret scanning enabled, including free public repositories, will automatically block commits containing this secret.

中文翻译

本周,我们推出了秘密扫描和公共监控的多项改进:Resend现已成为GitHub秘密扫描合作伙伴。秘密扫描现在可以检测来自APIclub和Resend的新秘密类型。秘密扫描现在默认通过推送保护阻止火山引擎秘密。secret_scanning_alert webhook现在包含secret_category字段(即default或generic),以便您可以区分特定类型和通用类型。公共监控警报列表现在在页面顶部显示洞察卡片,包括按归属分类的相关泄露细分、您的企业成员数量和已验证域名。GitHub秘密扫描通过搜索已知类型的秘密(如令牌和私钥)来保护用户。通过识别和标记这些秘密,我们的扫描有助于防止数据泄露和欺诈。我们已与Resend合作,扫描其令牌以帮助保护开发社区。GitHub将把在公共存储库中发现的任何暴露的秘密转发给Resend,Resend将采取适当行动,包括撤销秘密或通知相应管理员。了解更多关于秘密扫描合作伙伴计划的信息。如果您是秘密发行方,有兴趣与我们合作,可以通过向GitHub支持提交工单开始。秘密扫描现在会自动检测存储库中的以下新秘密类型。合作伙伴秘密在公共存储库中发现时,会通过秘密扫描合作伙伴计划自动报告给秘密发行方。用户秘密在公共或私有存储库中发现时,会生成秘密扫描警报。以下检测器现已默认包含在推送保护中。启用了秘密扫描的存储库(包括免费的公共存储库)将自动阻止包含此秘密的提交。

核心信息

GitHub本周推出了秘密扫描和公共监控的多项改进,包括新增合作伙伴Resend、新秘密类型检测、默认阻止火山引擎秘密、webhook增加字段、公共监控警报列表增加洞察卡片等。

  • GitHub本周推出了秘密扫描和公共监控的多项改进,包括新增合作伙伴Resend、新秘密类型检测、默认阻止火山引擎秘密、webhook增加字段、公共监控警报列表增加洞察卡片等。
  • 原贴提到:This week, we’re rolling out several improvements to secret scanning and
  • 来源:github.blog

详细解读

信号解读:GitHub持续强化其秘密扫描能力,从合作伙伴生态、检测类型、推送保护到监控界面,全面升级安全防护。这标志着开发者平台正从被动检测转向主动防御,并通过开放合作扩大覆盖范围。

为什么重要:秘密泄露是数据泄露和供应链攻击的主要源头。GitHub作为全球最大的代码托管平台,其安全改进直接影响数百万开发者和企业。新增合作伙伴机制使得秘密发行方能够快速响应泄露,缩短暴露窗口;默认阻止火山引擎秘密等新类型,减少了误操作风险;webhook字段增加有助于更精细的告警处理;公共监控的洞察卡片便于企业快速掌握泄露全貌。

对谁有价值:所有使用GitHub的开发者、企业DevOps团队、安全运维人员、以及秘密发行方(如API服务商)。开发者可减少意外提交秘密的风险;企业可更高效地监控内部仓库泄露;合作伙伴能自动接收泄露告警。

可以怎么行动:企业应确保启用秘密扫描和推送保护,配置webhook接收详细告警,并定期查看公共监控洞察卡片。秘密发行方可申请加入合作伙伴计划,以便自动接收泄露通知。开发者需注意新检测器加入推送保护,避免提交相关秘密。

风险或限制:秘密扫描并非100%覆盖所有秘密类型,且对私有仓库的扫描依赖于用户主动启用。合作伙伴计划需要申请和审核,可能影响覆盖速度。此外,自动阻止提交可能影响开发效率,需合理配置例外规则。

信息差价值

这条内容的真正价值,不只是“有人发布了一个新功能”,而是它揭示了 github.blog 背后的产品方向、工作流变化或竞争信号。对 OPC 来说,这种信息可以转化成持续追踪的栏目选题。

如果把《秘密扫描与公共监控的改进》放到你的内容系统里,它最大的价值在于帮助读者更快看懂“为什么值得关注”,而不是只看到一条碎片化动态。

参考来源

上一篇 AIHOT 日报参考 2026-07-16 下一篇 Grok Build 现已开源