How GitHub used secret scanning to reach inbox zero

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

GitHub's security team discovered 20,000+ secret scanning alerts across 15,000 repositories and reached inbox zero in nine months. Key findings: 90% of alerts were inactive (test fixtures, deactivated credentials), leaving ~2,000 real risks. Their phased approach covered enabling push protection everywhere, bulk-triaging noise, building custom validity checks for live credentials, solving repository ownership gaps, and tying remediation to engineering health metrics. Lessons include: validate before escalating, invest in durable ownership infrastructure, automate routing workflows, and make secret hygiene a shared engineering responsibility rather than a security-team-only burden.

10m read timeFrom github.blog
Post cover image
Table of contents
Cutting out the noiseSecrets don’t just live in codeOur phased approachPhase 1: Enable everywhere, stop the accumulationPhase 2: Understand and triagePhase 3: Validate what’s actually livePhase 4: Figure out who owns whatPhase 5: Manual triage for the long tailPhase 6: Systematize and drive accountabilityLessons learnedWhat this means for youTags:Written by
82 Impressions