Secret scanning has recently expanded coverage to GitHub discussions and pull requests.
GitHub is now performing a backfill scan, which will detect any historically existing secrets found in GitHub discussions and pull request bodies or comments.
For repositories with secret scanning enabled, if a secret is detected in a discussion or pull request, you will receive a secret scanning alert for it. Public leaks detected in public GitHub discussion or pull requests will also be sent to providers participating in the secret scanning partnership program.
Sign up for a 60 minute feedback session on secret scanning and be compensated for your time.
Learn how to secure your repositories with secret scanning or become a secret scanning partner.