Skip to content

Security: enable secret scanning non-provider patterns + validity checks (UI/settings) #34

Description

@CodeSolutionsLLC

Parent: #29

Outcome (2026-09-26)

Not available on this repository. Owner type is User (not Organization). GitHub documents Generic patterns (non-provider patterns) and Validity checks for partner patterns primarily for organization-owned repos with GitHub Secret Protection (Team+). On this User-owned public repo, the Settings UI does not offer usable Enable controls for those two extras, and API PATCH returns HTTP 200 but leaves both toggles disabled (silent no-op).

Already enabled (keep)

  • secret_scanning: enabled
  • secret_scanning_push_protection: enabled
  • dependabot_security_updates: enabled

Still disabled (expected / N/A here)

  • secret_scanning_non_provider_patterns
  • secret_scanning_validity_checks

If this repo later moves to an Organization + Secret Protection

Settings path (eligible org repos only):

  1. Repository → Settings
  2. Security and quality → Advanced Security
  3. Under Secret Protection: enable Generic patterns and/or Validity checks (then Save changes if prompted)

Direct settings URL shape: https://github.com/<org>/<repo>/settings/security_analysis

Docs:

Recommendation

Close this issue as N/A / account limitation. Optional later epic only if the repo is transferred to an Organization and Secret Protection is purchased.

Activity

  1. changed the title [-]Security: enable secret scanning non-provider patterns + validity checks (UI/Computer)[/-] [+]Security: enable secret scanning non-provider patterns + validity checks (Settings UI)[/+] on Sep 26, 2026
  2. CodeSolutionsLLC commented on Sep 26, 2026

    @CodeSolutionsLLC
    OwnerAuthor

    UPDATED 2026-09-26: Confirmed N/A for User-owned public repo — Generic patterns / Validity checks require org ownership + Secret Protection. Base secret scanning + push protection already on. API PATCH remains a silent no-op. Recommend close as N/A.

  3. changed the title [-]Security: enable secret scanning non-provider patterns + validity checks (Settings UI)[/-] [+]Security: enable secret scanning non-provider patterns + validity checks (UI/settings)[/+] on Sep 26, 2026
  4. CodeSolutionsLLC commented on Sep 26, 2026

    @CodeSolutionsLLC
    OwnerAuthor

    CLOSED N/A 2026-09-26: User-owned public repo — Generic patterns / Validity checks require Organization + Secret Protection. Base secret scanning + push protection already enabled. Exact PASS on final body.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions