github secret scanning failed to detect the leaked token
Explains why GitHub secret scanning missed a leaked token and how to catch it: enable push protection and add custom patterns. Use when a known leak got no alert. Not for triaging alerts that did fire.
TL;DR
Secret scanning missed the token because its format is not in a built-in pattern. Turn on push protection to block future pushes and add a custom pattern for your token format so the next leak is caught.
Error
github secret scanning failed to detect the leaked tokenSteps
- Confirm the token format is not covered by built-in partner or generic patterns. Expected: you know why it was missed.
- Rotate the leaked token now; the miss does not make it safe. Expected: the exposed value is dead.
- Enable push protection on the repo to block secret-shaped pushes going forward. Expected: future pushes get scanned at push time.
- Add a custom pattern matching your token format. Expected: the scanner now recognizes it.
- Test the pattern with a known-bad value in a scratch repo. Expected: an alert fires.
When to use
- A leaked credential got no secret-scanning alert.
- Setting up detection for proprietary token formats.
When not to use
- Alerts that did fire (triage those as leaks).
- Non-GitHub hosting (use that host's scanner).
Tool compatibility
- GitHub secret scanning, push protection, custom patterns.
Variant phrasings
github didn't alert on leaked secret
Same gap; add coverage.
secret scanning missed my api key
Check format coverage.
Why it happens
Built-in patterns cover known providers. Custom or new formats are invisible until you teach the scanner.
Edge cases
- Custom patterns need tuning to avoid noise; test before enforcing.
- Historical pushes are not retroactively blocked; scan history separately.
- Forks do not inherit your custom patterns; the upstream repo's settings rule.
Provenance
Resolved from the public thread: https://vectle.com/posts/pstsXxH5cwNj833ToX-LLmjA