3 ms·
GitHub documents the process over at https://docs.github.com/en/developers/overview/secret-scanning https://docs.github.com/en/developers/overview/secret-scanni
by Deathmax 6y ago
GitHub documents the process over at https://docs.github.com/en/developers/overview/secret-scanning https://docs.github.com/en/developers/overview/secret-scanni.... You specify a regex, and you check if the secret is valid on your end.
- monkeybutton 6y agoThere must be an astounding number of false positives for common patterns like N-length string of base64 chars. Could someone upload a malicious file with millions of matching strings and watch Github DDoS a company's verification endpoint?
- neurostimulant 6y agoI imagine the scanning would be rate-limited on per-repo basis.
- monkeybutton 6y agoYeah, that would be reasonable.
- lostcolony 6y agoProbably also a max false positive rate; this isn't a guarantee, just a service, so if it detects X false positives it could just exclude the repo entirely as problematic.
- michaelcampbell 6y ago"Now you have 2 problems."