How GitHub used secret scanning to reach inbox zero
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
GitHub's security team discovered 20,000+ secret scanning alerts across 15,000 repositories and reached inbox zero in nine months. Key findings: 90% of alerts were inactive (test fixtures, deactivated credentials), leaving ~2,000 real risks. Their phased approach covered enabling push protection everywhere, bulk-triaging noise, building custom validity checks for live credentials, solving repository ownership gaps, and tying remediation to engineering health metrics. Lessons include: validate before escalating, invest in durable ownership infrastructure, automate routing workflows, and make secret hygiene a shared engineering responsibility rather than a security-team-only burden.