Improvement

March 17, 20261 Minute Read

Push protection exemptions for roles, teams, and apps

Organizations with secret scanning push protection can now designate specific roles, teams, and apps as exempt from push protection enforcement.

Exemption status is evaluated at the time of each push. When an exempt actor pushes content containing secrets, push protection is skipped and no bypass requests are created.

Exemptions can be configured at the organization and enterprise levels with security configurations.

Learn more about secret scanning and push protection bypasses and exemptions.

Subscribe to our developer newsletter

Discover tips, technical guides, and best practices in our biweekly newsletter just for devs.

By submitting, I agree to let GitHub and its affiliates use my information for personalized communications, targeted advertising, and campaign effectiveness. See the GitHub Privacy Statement for more details.

Push protection exemptions for roles, teams, and apps - GitHub Changelog