Skip to content

Why GitHub sends my hardcoded secrets to the providers when Secret Scanning is disabled? #55126

Discussion options

You must be logged in to vote

The short answer

More details

You've mentioned that you've disabled secret scanning, but you're still seeing authentication events from AWS. This is because secret scanning for partners is always enabled for public repositories, even if you've disabled secret scanning for your own repository.

Secret scanning for partners is a security feature that helps to protect your open source community and partners' services from abuse. When you …

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by 15MariamS
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Secret Scanning Code Security Build security into your GitHub workflow with features to keep your codebase secure Question
2 participants