Skip to content
Signpost
Rolling outSecurity

Secret scanning and push protection

Blocks commits containing credentials before they reach a remote branch, and flags secrets already in history so they can be rotated.

Lifecycle

Next: generally available on 1 December 2026, in 8 weeks.

  1. Proposed6 months ago
  2. In development4 months ago
  3. Rolling out (current stage)3 weeks ago
  4. Generally availableplanned, in 8 weeks

Detail

What this is

Two things: scanning existing history for credentials that have leaked, and blocking new commits that contain them.

Who this affects

Everyone who pushes code. In practice most teams see nothing — the report-only phase since June found issues in roughly one repository in six, and those teams have already been contacted.

What we need from you

Nothing in advance. When a push is blocked, follow the runbook: rotate, then clean up.

Updates

Action required

Push protection is on for the 20 busiest repositories

If a push is blocked, the message names the file and line. Rotate the credential first, then remove it from the commit — do not just force-push over it, because the secret is already in the reflog.

Rolling out to the remaining repositories through October and November.

Info

Scanning runs in report-only mode across every repository

No pushes are blocked yet. Findings go to the owning team's channel so you can start rotating without a deadline hanging over you.