Just one command can help you stop leaking secrets into your public code. Give your repositories essential security hygiene with gh-secure from the GitHub Security Lab. ✅ Install and use it in the Copilot app, Copilot CLI, or GitHub CLI. gh.io/gh-secure

Oct 1, 2026 · 5:05 PM UTC

44
66
533
82,993
Sort replies: Relevant Recent Liked
Replying to @github
Pair gh-secure with a rehearsed response to a real finding: revoke the exposed credential before cleaning up the file. Deleting a key from the latest commit does not make the copy in someone's clone stop working.
82
Replying to @github
ファーストビューで惹きつけても肝心の内容が崩れたら意味がない。 シークレット管理はセキュアコーディングの要、 情報漏洩リスクを未然に抑える仕組みです。 デザインでいうと、見た目の良さだけでなく 「中身の健全さ」が秘訣の味付けみたいなもの。
115
Replying to @github
@grok If a single CLI command like gh-secure catches leaked secrets, why do studies still find that over 10 million secrets are exposed on GitHub annually, does tooling awareness lag that far behind adoption, or is the detection itself incomplete?
2
1
410
Replying to @github
This is so true
44
Replying to @github
i'd peck the secrets out myself, but apparently there's a command for that
292
Replying to @github
Issues and pull requests created by agents can also leak secrets. Check them too, not just the code.
2
89
Replying to @github
gh-secure + un comando es higiene mínima. Tip para repos de clases y hackathons en Colombia: activen secret scanning en CI antes del primer push público, no después del screenshot viral. Checklist: keys rotadas, .env en .gitignore, y un job que falle el PR si encuentra token. ¿gh-secure cubre también notebooks .ipynb?
1
148
Replying to @github
one command to stop leaking secrets. the secrets already starred the repo and left.
1
210
Replying to @github
secrets leak at commit, not at install
1
158
Replying to @github
If a key has already reached a public repo, revoke or rotate it first. Rewriting Git history won't erase copies in other people's clones. GitHub's cleanup guide starts with revocation for that reason: docs.github.com/en/authentic…
2
142
Replying to @github
Interesting
1
53
Replying to @github
One command for secret hygiene is long overdue. Agent diffs make it too easy to miss a key.
2
133
Replying to @github
cool, now fix copilot writing the bugs that leak them
1
21