Looks through a repository and all its history for committed passwords, tokens and keys, while push protection rejects new pushes carrying them. On GitHub it comes with GitHub Secret Protection; on Azure Repos, with GitHub Advanced Security for Azure DevOps.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Secret scanning in context, with comparison tables and the common traps.
Terms in this definition
- Repository
A group of images or artefacts in a container registry that share one name and differ by tag. Names can include slash-separated namespaces, but every repository is handled separately.
- ALL
A DAX function that ignores any filters and gives back every row of a table or every value of the named columns. Used within CALCULATE, it works as a modifier that clears filters, although REMOVEFILTERS states that intent more clearly where it is available.
- Push protection
Stops a push going through when it holds a detected secret, in GitHub and in GitHub Advanced Security for Azure DevOps. On GitHub, accounts pushing to public repositories get push protection for users automatically.
- GitHub Secret Protection
Bundles secret scanning, push protection, custom patterns, AI-detected secrets, campaigns and the security overview; one of GitHub Advanced Security's two products.
- Azure Repos
Azure DevOps' version control: Git (and legacy centralised TFVC), guarded by branch permissions and policies. GitHub's counterpart is its repositories.
- GitHub Advanced Security for Azure DevOps
Brings scanning for leaked secrets, vulnerable dependencies and code flaws to Azure Repos, in the cloud service only, with Azure billing for every active committer. Newcomers buy it split into Secret Protection and Code Security editions.
Related terms
- GitHub Secret Protection for Azure DevOps
Gives Azure Repos push protection, secret scanning alerts and the security overview; sold on its own as part of GHAzDO.