Stops a push going through when it holds a detected secret, in GitHub and in GitHub Advanced Security for Azure DevOps. On GitHub, accounts pushing to public repositories get push protection for users automatically.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Push protection in context, with comparison tables and the common traps.
Terms in this definition
- Real-time streaming semantic model
Covers live-fed push, streaming and PubNub models, plus streaming dashboard tiles. Microsoft now steers people towards Real-Time Intelligence in Fabric, as these are being retired and new ones can only be made until 31 October 2027.
- Secret
Object in Key Vault storing an arbitrary string value, for instance a password, API key or connection string.
- GitHub Advanced Security for Azure DevOps
Brings scanning for leaked secrets, vulnerable dependencies and code flaws to Azure Repos, in the cloud service only, with Azure billing for every active committer. Newcomers buy it split into Secret Protection and Code Security editions.
- AGDLP
Nesting pattern: users go into global groups, which go into domain local groups, which receive the permissions. AGUDLP adds universal groups for forests with several domains.
- Get
Key Vault permission on secrets that allows a single secret to be read; App Service Key Vault references need nothing beyond it.
Related terms
- GitHub Secret Protection
Bundles secret scanning, push protection, custom patterns, AI-detected secrets, campaigns and the security overview; one of GitHub Advanced Security's two products.
- GitHub Secret Protection for Azure DevOps
Gives Azure Repos push protection, secret scanning alerts and the security overview; sold on its own as part of GHAzDO.
- Secret scanning
Looks through a repository and all its history for committed passwords, tokens and keys, while push protection rejects new pushes carrying them. On GitHub it comes with GitHub Secret Protection; on Azure Repos, with GitHub Advanced Security for Azure DevOps.