Secret scanning
We scan your connected GitHub repositories daily for committed credentials. We store where each one sits and a keyed hash, never the credential.
Secret Scanning is an Enterprise add-on, granted by agreement. Once a day we read the default branch of every repository your GitHub installation covers and list each credential-shaped string under Integrations > Secret Scanning, with a link to the file and line on GitHub.
We read through the Penv Cloud GitHub App (install it from Machine Identities > Connect a Platform) with a token limited to contents: read and metadata: read.
We skip a suspended installation. The page names it, even beside a live one, and its open findings stay listed until you unsuspend it and the next scan runs.
What we detect
| Rule | Matches |
|---|---|
| AWS access key | AKIA… or ASIA… key ids |
| GitHub token | ghp_, gho_, ghu_, ghs_, ghr_ and github_pat_ tokens |
| Stripe live key | sk_live_ and rk_live_ keys |
| Slack token | xox… tokens |
| Google API key | AIza… keys |
| Private key | PEM BEGIN … PRIVATE KEY headers |
| Penv Cloud credential | pck_, pcu_ and pce_ credentials |
What we store
| Field | Stored |
|---|---|
| Repository, path, line | yes |
| Rule | yes |
| The matched string | no: we keep an HMAC of it, so the same credential in the same file is one finding |
A finding closes on the first complete scan that no longer sees it. To close one, rotate the credential, then remove it from the branch: deleting it from the branch alone leaves it in git history.
Limits
| Limit | Value |
|---|---|
| Files read per repository per scan | 300 |
| Largest file read | 200 KB |
| Skipped | images, fonts, archives, PDFs, .lock files, node_modules, vendor, dist, build |
A repository with more files than the limit is scanned in part, and its open findings stay open until a complete scan. Each scan lands a scanning.repository_scanned entry in the audit log.