Improvement

July 29, 20251 Minute Read

Secret scanning adds validity checks for Doppler, Midtrans, Onfido, Postman, and Segment

Secret scanning is adding validity check support for eight additional token types across five providers. In addition to previously announced token types, you will now see validity checks for the following token types:

ProviderPatternValidity
Dopplerdoppler_service_account_token
Midtransmidtrans_production_server_key
Midtransmidtrans_sandbox_server_key
Onfidoonfido_live_api_token
Onfidoonfido_sandbox_api_token
Postmanpostman_api_key
Postmanpostman_collection_key
Segmentsegment_public_api_token

What are validity checks?

Validity checks indicate if the leaked credentials are active and could still be exploited. If you’ve previously enabled validation checks for a given repository, GitHub will now automatically verify validity for alerts on supported token types. View the full list of supported secret types in our product documentation.

Subscribe to our developer newsletter

Discover tips, technical guides, and best practices in our biweekly newsletter just for devs.

By submitting, I agree to let GitHub and its affiliates use my information for personalized communications, targeted advertising, and campaign effectiveness. See the GitHub Privacy Statement for more details.

Secret scanning adds validity checks for Doppler, Midtrans, Onfido, Postman, and Segment - GitHub Changelog