Concept and mechanism
A committed credential should be treated as compromised. Deleting its line or rewriting history does not invalidate the issuer-side value or remove copies already obtained. Response coordinates revocation or rotation, consumer updates, and misuse investigation. Validity state active, inactive, or unknown describes a specific check; unknown does not mean safe. Some issuers or credential types require additional context for validation. Alert lifecycle is another dimension: removing a token from code does not automatically close its alert. After confirming necessary actions, document reason and evidence when closing through the applicable review flow. Preserve enough information to explain decisions without redistributing the secret itself.
Guided application
In a fictional batch service, token replacement can affect several jobs and teams. Identify consumers and decide containment with owners without turning continuity into a reason to retain an exposed credential indefinitely. Push protection reduces new exposures of detectable patterns, but personal and repository scopes have different behavior. Bypass overrides a block; Exempt skips protection for the actor. For internal patterns, rehearse expressions against representative data and negative examples before blocking entire teams. Editing a pattern can close old alerts because the detector changed. Explain that count reduction separately from credentials actually revoked.
Alert closed after regex editing, token still active: that state change did not resolve the risk.
Common pitfalls
Removal as revocation; unknown as inactive; bypass as exemption; fewer alerts as less exposure.
Related topics: Products, scope, and prevention · Dependencies, inventory, and merge prevention · CodeQL, coverage, and SARIF results
Keep the credential, check, alert, and exception decision separate.
Reference: Resolve exposed secrets · GH-500 skills measured July2026;study guide updated2026-05-14