Security todo
GitHub secret scanning and push protection status could not be read (security_and_analysis is null; needs admin access). For a public repo that handles publish tokens (CARGO_REGISTRY_TOKEN, HOMEBREW_TAP_GITHUB_TOKEN), enabling secret scanning + push protection catches an accidentally committed key before it lands and blocks an attacker from quietly committing one. Enable both in Settings → Code security and analysis.
Context
- Severity: High
- Category: account_access_control
- Confidence: Unverified
- Threat: Attacker with repo write access / compromised contributor — a leaked or planted credential commits without detection.
Evidence
metadata.security_and_analysis is null; branch_protection/security endpoints returned forbidden.
Security todo
GitHub secret scanning and push protection status could not be read (security_and_analysis is null; needs admin access). For a public repo that handles publish tokens (CARGO_REGISTRY_TOKEN, HOMEBREW_TAP_GITHUB_TOKEN), enabling secret scanning + push protection catches an accidentally committed key before it lands and blocks an attacker from quietly committing one. Enable both in Settings → Code security and analysis.
Context
Evidence
metadata.security_and_analysis is null; branch_protection/security endpoints returned forbidden.