Improvement

August 26, 20251 minute read

Secret scanning adds 10+ new validators, including Square, Wakatime, and Yandex

Secret scanning is adding validity check support for several additional secret types across multiple providers. In addition to previously announced validators, GitHub is adding validity check support for the following token types:

ProviderPatternValidity
Bitrisebitrise_workspace_api_token✓
Groqgroq_api_key✓
Siemenssiemens_api_token✓
Squaresquare_access_token*✓
Uniwisewiseflow_api_key✓
Wakatimewakatime_api_key✓
Wakatimewakatime_oauth_access_token✓
WorkOSworkos_staging_api_key✓
WorkOSworkos_production_api_key✓
Yandexyandex_cloud_iam_token✓

* Validation is available for the following token versions: Square Access Token, Legacy Production Access Token, and Legacy Sandbox Access Token.

What are validity checks?

Validity checks indicate if the leaked credentials are active and could still be exploited. If you’ve previously enabled validity checks for a given repository, GitHub will now automatically verify validity for alerts on supported token types. View the full list of supported secret types in our product documentation.

Subscribe to our developer newsletter

Discover tips, technical guides, and best practices in our biweekly newsletter just for devs.

By submitting, I agree to let GitHub and its affiliates use my information for personalized communications, targeted advertising, and campaign effectiveness. See the GitHub Privacy Statement for more details.

Secret scanning adds 10+ new validators, including Square, Wakatime, and Yandex - GitHub Changelog