Improvement

May 20, 20252 Minute Read

Secret Protection expands default pattern support (May 2025)

GitHub continually updates the default pattern set for secret scanning with new patterns and upgrades of existing patterns, helping ensure your repositories have comprehensive detection for different secret types.

The following new patterns were added over the past month. Secret scanning automatically detects any secrets matching these patterns in your repositories. See the full list of supported secrets in the documentation.

ProviderTokenPartnerUserPush protection
Block Protocolblock_protocol_api_key
Datadogdatadog_rcm
Dockerdocker_organization_access_token
Dockerdocker_swarm_join_token
Dockerdocker_swarm_unlock_key
Groqgroq_api_key
Herokuheroku_platform_api_oauth2_token
Herokuheroku_postgres_connection_url
MongoDBmongodb_atlas_service_account_secret
Salesforcesalesforce_oauth2_consumer_key salesforce_oauth2_consumer_secret
Salesforcesalesforce_refresh_token
xAIxai_api_key

The following existing patterns have been updated. Existing alerts are not affected by pattern updates.

UpdateProviderToken
Updated detector for new pattern formatAsaasasaas_api_token
Updated detector for increased precisionFastlyfastly_api_token
Newly added to push protectionDynatracedynatrace_api_token
Newly added to partner alertingGooglegoogle_cloud_storage_access_key_secret
Newly added to partner alertingGooglegoogle_cloud_storage_service_account_access_key_id
Newly added to partner alertingGooglegoogle_oauth_access_token
Newly added to partner alertingGooglegoogle_oauth_client_id
Newly added to partner alertingGooglegoogle_oauth_client_secret
Newly added to partner alertingGooglegoogle_oauth_refresh_token

Learn more about securing your repositories with secret scanning.

Subscribe to our developer newsletter

Discover tips, technical guides, and best practices in our biweekly newsletter just for devs.

By submitting, I agree to let GitHub and its affiliates use my information for personalized communications, targeted advertising, and campaign effectiveness. See the GitHub Privacy Statement for more details.

Secret Protection expands default pattern support (May 2025) - GitHub Changelog