Files
llm-wiki/raw/articles/github-secret-scanning-public-monitoring-2026.md
T
2026-07-03 00:38:05 +09:00

57 lines
4.7 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
---
source_url: "https://github.blog/changelog/2026-07-01-secret-scanning-public-monitoring-for-enterprises"
ingested: 2026-07-02
sha256: ae19f067ce45eb4276134783397cb916dcae5f2d4302727a96509f49c0d81446
discovered_from:
platform: discord
channel_id: "1477793137064935675"
channel_name: "tw"
message_id: "1522095047607193600"
author_id: "1477793167486226708"
posted_at: "2026-07-02T04:22:18.508000000Z"
message_excerpt: "Public monitoring for secret scanning は、GitHub上の公開面から企業シークレット漏洩を監視する新機能で、守りの運用設計に直結します。"
---
[Back to changelog](https://github.blog/changelog/)
GitHub is committed to empowering the developer community by helping organizations recognize and address the risks of secret leaks wherever they happen. We believe every enterprise should know the moment its secrets leak in public, no matter **where** it happens on GitHub. That’s why public monitoring is now in public preview for enterprises with GitHub Secret Protection, at no additional cost.
Secrets don’t respect boundaries; scanning for them shouldn’t either.
![Public monitoring list view shown in the security overview UI](https://github.com/user-attachments/assets/ab9f595d-0d4d-45f8-afe9-8e25d235c862)
### What is public monitoring?
GitHub monitors the entire public surface of github.com for leaked secrets in real time. Public monitoring attributes those secrets back to your enterprise, based on where your people commit.
![Public monitoring slide-out panel with details about a finding](https://github.com/user-attachments/assets/07b0c259-ce77-4c7f-9c42-a100bb55f2cf)
Secret scanning has always protected the repositories you own. But secrets leak beyond that boundary. For example, a developer commits to a personal fork or an open source project, or they paste a token into a public issue or pull request, and this often happens from an account your security team isn’t tracking. Exposures like these were nearly impossible to find and often only surfaced after they’d been abused by bad actors.
Public monitoring closes that gap. It finds these vulnerabilities and attributes them to your enterprise so you can respond quickly. The feature scans for secrets exposed anywhere in public content across github.com—including git content, pull request comments, and GitHub issues—and natively attributes each one back to your enterprise, through GitHub’s identity layer and verified domains.
Because the activity happens on GitHub, so does the attribution: in real time (not a nightly async crawl), definitively with native platform metadata (not on a guess from a commit email), and across arbitrary public repositories (not just surfaces where you tell us to look).
Public monitoring works “out of the box” with no setup or configuration required; just enable it and start seeing results.
### How does attribution work?
GitHub attributes a public finding to your enterprise using two main heuristics, leveraging metadata across GitHub’s identity layer, domain verification, and token metadata.
| Method | What it checks | Catches |
| --- | --- | --- |
| Member-based attribution | The committer’s GitHub account belongs to your enterprise as an enterprise member | Leaks from managed accounts and known members |
| Verified domain matching | The committer’s email is on a domain your organization or enterprise has [verified](https://docs.github.com/enterprise-cloud@latest/admin/configuration/configuring-your-enterprise/verifying-or-approving-a-domain-for-your-enterprise) | Leaks from personal accounts using a work email |
Verified domain matching applies even when the account isn’t linked to your enterprise and even when the email isn’t public. Each finding shows which method attributed it, along with the secret type, the public location (e.g. file, issue, pull request, discussion, etc.), and the committer.
### How to enable public monitoring?
Enterprise owners and enterprise security managers can enable public monitoring from their **Security** tab. Once enabled, you’ll see recently leaked secrets, and GitHub will begin scanning for future matches.
Public monitoring is available for GitHub Enterprise Cloud customers with Secret Protection or Advanced Security. Support for Enterprise Cloud with data residency is coming soon.
### Learn more
Learn more about [secret scanning](https://docs.github.com/code-security/secret-scanning/introduction/about-secret-scanning) and [public monitoring](https://docs.github.com/enterprise-cloud@latest/code-security/concepts/secret-security/public-monitoring) in our product documentation. Have feedback? Let us know by [joining the discussion](https://gh.io/community-secret-scanning) —we’re listening.