GitHub has two completely separate tools for protecting secrets, and most developers only know about one. In this video, I break down secret scanning vs push protection, show why a push was blocked even when secret scanning was disabled, and walk through a real alert and full remediation flow.
──────────────────────────────
📌 WHAT YOU'LL LEARN
──────────────────────────────
→ The difference between secret scanning and push protection
→ Why push protection has TWO levels: user-level and repository-level
→ How to enable secret scanning in a public repository
→ How a leaked token appears as a real GitHub security alert
→ The correct remediation order: rotate → switch → revoke → review logs → close
→ How to close an alert with the right resolution (false positive, revoked, used in testing)
──────────────────────────────
🔗 RELATED
──────────────────────────────
GitHub Secret Scanning docs → https://docs.github.com/en/code-secur...
GitHub Push Protection docs → https://docs.github.com/en/code-secur...
Supported secret patterns → https://docs.github.com/en/code-secur...
──────────────────────────────
This is the final video in this GitHub security series. If this was useful, leave a like, it helps more than you think.
#GitHubSecurity #SecretScanning #PushProtection
──────────────────────────────
Time Passing By by Audionautix is licensed under a Creative Commons Attribution 4.0 license. https://creativecommons.org/licenses/...
Artist: http://audionautix.com/