Skip to main content

Enterprise Server 3.21 est actuellement disponible en tant que version candidate.

Sécuriser vos secrets à grande échelle avec GitHub

Les informations d’identification divulguées exposent votre organisation à des violations de données. GitHub Protection secrète détecte et empêche automatiquement les fuites de secrets. Suivez ce parcours d’adoption pour évaluer les risques, piloter la solution et étendre la protection à l’ensemble de l’organisation.

1

Phase 1: Assess your current secret risk

4 Articles10 minutes to run, 30 minutes to analyze results

Run a free secret risk assessment (SRA) to understand your organization exposure and establish baseline metrics. Before purchasing GHSP, identify how many secrets are exposed across your organization and build a data-driven business case for the investment.

  1. Risques de fuite de secrets
  2. Exécution de l’évaluation des risques secrets pour votre organisation
  3. Interpreting secret risk assessment results
  4. Affichage de vos rapports d’évaluation des risques de sécurité
2

Phase 2: Evaluate GitHub Secret Protection

6 Articles2-4 hours

Determine if GHSP meets your needs and build a business case. Review detection capabilities, push protection features, and validity checking. Use the pricing calculator to estimate costs and calculate potential cost savings from preventing manual remediation.

  1. Secret scanning
  2. Push protection
  3. Modèles de détection de secrets pris en charge
  4. Estimating the price of Secret Protection
  5. Calculating the cost savings of push protection
  6. Configuration d’un essai de GitHub Advanced Security
3

Phase 3: Pilot GitHub Secret Protection

4 Articles2-4 weeks

Run a pilot to validate GHSP with a small set of repositories before organization-wide enablement. Select 5-10 repositories with active development and known secret exposure. If you estimated pricing in Phase 2, you'll confirm costs as part of the enablement flow. A successful pilot demonstrates security value quickly, identifies workflow adjustments, and gathers feedback to refine your rollout strategy.

  1. Best practices for selecting pilot repositories
  2. Tarification et activation GitHub Secret Protection
  3. Enabling push protection for your repository
  4. Corriger une exposition de secret dans votre référentiel
4

Phase 4: Monitor and assess value

3 Articles1-2 hours per week during pilot

Track metrics to demonstrate ROI and identify areas for improvement. Monitor how many secrets are being detected, how often developers bypass push protection, and how quickly leaked secrets are remediated. Use these insights to refine your rollout strategy, prove value to stakeholders, and justify organization-wide deployment.

  1. Évaluation de l’impact de la protection secrète GitHub
  2. Mesures de protection contre les opérations push d'analyse des secrets
  3. Évaluation des alertes à partir de l’analyse des secrets
5

Phase 5: Scale, customize, and automate

4 Articles1-2 weeks for initial rollout, ongoing for optimization

Expand GHSP organization-wide and tailor it to your specific workflows. Use validity checks to prioritize remediation, define custom patterns for organization-specific secrets, and apply security configurations at scale. For advanced use cases, enable AI-powered detection and integrate with automated workflows.

  1. Applying a custom security configuration
  2. Defining custom patterns for secret scanning
  3. Enabling delegated bypass for push protection
  4. Activation de l’analyse du secret pour les modèles non fournisseurs
1

Phase 1: Assess your current secret risk

4 Articles10 minutes to run, 30 minutes to analyze results

Run a free secret risk assessment (SRA) to understand your organization exposure and establish baseline metrics. Before purchasing GHSP, identify how many secrets are exposed across your organization and build a data-driven business case for the investment.

  1. Risques de fuite de secrets
  2. Exécution de l’évaluation des risques secrets pour votre organisation
  3. Interpreting secret risk assessment results
  4. Affichage de vos rapports d’évaluation des risques de sécurité
2

Phase 2: Evaluate GitHub Secret Protection

6 Articles2-4 hours

Determine if GHSP meets your needs and build a business case. Review detection capabilities, push protection features, and validity checking. Use the pricing calculator to estimate costs and calculate potential cost savings from preventing manual remediation.

  1. Secret scanning
  2. Push protection
  3. Modèles de détection de secrets pris en charge
  4. Estimating the price of Secret Protection
  5. Calculating the cost savings of push protection
  6. Configuration d’un essai de GitHub Advanced Security
3

Phase 3: Pilot GitHub Secret Protection

4 Articles2-4 weeks

Run a pilot to validate GHSP with a small set of repositories before organization-wide enablement. Select 5-10 repositories with active development and known secret exposure. If you estimated pricing in Phase 2, you'll confirm costs as part of the enablement flow. A successful pilot demonstrates security value quickly, identifies workflow adjustments, and gathers feedback to refine your rollout strategy.

  1. Best practices for selecting pilot repositories
  2. Tarification et activation GitHub Secret Protection
  3. Enabling push protection for your repository
  4. Corriger une exposition de secret dans votre référentiel
4

Phase 4: Monitor and assess value

3 Articles1-2 hours per week during pilot

Track metrics to demonstrate ROI and identify areas for improvement. Monitor how many secrets are being detected, how often developers bypass push protection, and how quickly leaked secrets are remediated. Use these insights to refine your rollout strategy, prove value to stakeholders, and justify organization-wide deployment.

  1. Évaluation de l’impact de la protection secrète GitHub
  2. Mesures de protection contre les opérations push d'analyse des secrets
  3. Évaluation des alertes à partir de l’analyse des secrets
5

Phase 5: Scale, customize, and automate

4 Articles1-2 weeks for initial rollout, ongoing for optimization

Expand GHSP organization-wide and tailor it to your specific workflows. Use validity checks to prioritize remediation, define custom patterns for organization-specific secrets, and apply security configurations at scale. For advanced use cases, enable AI-powered detection and integrate with automated workflows.

  1. Applying a custom security configuration
  2. Defining custom patterns for secret scanning
  3. Enabling delegated bypass for push protection
  4. Activation de l’analyse du secret pour les modèles non fournisseurs