4 ms·
Any string that matches access token regexp provided by Tencent (see https://docs.github.com/en/developers/overview/secret-scanning-partner-program https://docs
by AlbertVAustin 4y ago
Any string that matches access token regexp provided by Tencent (see https://docs.github.com/en/developers/overview/secret-scanning-partner-program https://docs.github.com/en/developers/overview/secret-scanni...).
- plugin-baby 4y ago.* ;-)
- Pathogen-David 4y agoFor public repositories only though. For private repos it's optional, and when enabled the repo admins get an alert to handle it themselves without it going to the vendor.
- ilyt 4y agoSo it is just one bad regexp away from sending them other companies secrets
- mukesh610 4y agoI don't see what your comment is trying to point out. The same could be said for all the other Secret Scanning partners GitHub has, like AWS and so on. That being said, it's impossible that a "bad regexp" is gonna make its way to the GitHub codebase.