GitHub has launched a free public preview of "public monitoring" for Enterprise Cloud customers who have Secret Protection enabled. The system scans all public surfaces on github.com, including code, pull requests, issue comments, and discussion comments in real time.
Once a leaked credential associated with the company is detected, the system instantly identifies and notifies the correct organization using the platform's identity layer and verified domains — even if the person who leaked it used a personal account not tied to the company or their email is private. This solves the pain point where employees accidentally expose work keys in personal repos or open source projects while security teams remain completely in the dark. The new feature helps companies revoke those credentials before they can be exploited. It works out of the box and never scans any private repositories.