Improvement

August 12, 20251 Minute Read

Secret scanning adds 12 validators including Cockroach Labs, Polar, and Yandex

Secret scanning is adding validity check support for 12 additional token types across 11 providers. In addition to previously announced token types, you will now see validity checks for the following token types:

ProviderPatternValidity
Apifyapify_api_token
Asaasasaas_api_token
Cockroach Labsccdb_api_key
Fullstoryfullstory_api_key*
Grafanagrafana_cloud_api_token
Polarpolar_access_token**
RunPodrunpod_api_key
Sourcegraphsourcegraph_instance_identifier_access_token
Sourcegraphsourcegraph_access_token
Telnyxtelnyx_api_v2_key
Val Townval_town_api_token
Yandexyandex_cloud_api_key

* Includes support for the Fullstory API Key Legacy and Fullstory API Key versions.
** Includes support for the Polar Access Token and Polar Legacy API Token versions.

What are validity checks?

Validity checks indicate if the leaked credentials are active and could still be exploited. If you’ve previously enabled validation checks for a given repository, GitHub will now automatically verify validity for alerts on supported token types. View the full list of supported secret types in our product documentation.

Subscribe to our developer newsletter

Discover tips, technical guides, and best practices in our biweekly newsletter just for devs.

By submitting, I agree to let GitHub and its affiliates use my information for personalized communications, targeted advertising, and campaign effectiveness. See the GitHub Privacy Statement for more details.

Secret scanning adds 12 validators including Cockroach Labs, Polar, and Yandex - GitHub Changelog