https://tailscale.com/blog/github-secret-scanning
Introducing GitHub secret scanning for Tailscale secrets
Jan 22, 2025 - Today we’re announcing a secret scanning integration between Tailscale and GitHub, the world’s largest source code host. This collaborative effort marks...
introducing githubsecret
https://bitwarden.com/blog/using-bitwarden-secrets-manager-and-github-actions/
Using Bitwarden Secrets Manager and GitHub Actions to upload an app marketplace | Bitwarden
Streamline your development processes and securely inject secrets into a GitHub workflow with Bitwarden Secrets Manager and GitHub Actions.
bitwarden secrets manager
https://github.blog/developer-skills/github/github-protips-tips-tricks-hacks-and-secrets-from-jason-etcovitch/
GitHub Protips: Tips, tricks, hacks, and secrets from Jason Etcovitch - The GitHub Blog
May 14, 2021 - From GitHub Actions and magic URLs to gists, check out Jason Etcovich’s top ten tips and tricks to help you hack your GitHub experience.
github protipstricks hacks
https://github.blog/news-insights/the-library/unlock-github-secrets-next-techs-break-the-code-2/
Unlock all the GitHub secrets within .Tech Domains newest experience: Break The Code 2! - The...
github secretsunlockwithin
https://www.percona.com/blog/storing-kubernetes-operator-for-percona-server-for-mongodb-secrets-in-github/
Storing Kubernetes Operator for Percona Server for MongoDB Secrets in Github
Mar 22, 2021 - Use GitOps and keep Kubernetes secrets for Percona Kubernetes Operator for Percona Server for MongoDB securely in the repository with Sealed Secrets or Vault...
percona server mongodbstoring
https://www.cve.news/cve-2025-30066/?ref=jessehouwing.net
CVE-2025-30066 - How Malicious Commits in tj-actions/changed-files Leaked GitHub Secrets
In March 2025, the popular GitHub Action named tj-actions/changed-files faced a major supply chain security incident. This vulnerability, tracked as...
cvemaliciouscommitstjactions
https://www.csoonline.com/article/4103717/github-action-secrets-arent-secret-anymore-exposed-pats-now-a-direct-path-into-cloud-environments-2.html
GitHub Action Secrets aren’t secret anymore: exposed PATs now a direct path into cloud...
Dec 10, 2025 - Wiz has found threat actors exploiting GitHub tokens, giving them access to GitHub Action Secrets and, ultimately, cloud environments.
github actionsecret anymore
https://www.wiz.io/blog/s1ngularity-supply-chain-attack
s1ngularity: supply chain attack leaks secrets on GitHub: everything you need to know | Wiz Blog
Aug 27, 2025 - Detect and mitigate a critical supply chain compromise affecting the Nx NPM Package. Organizations should act urgently.
supply chain attackleaks
https://github.com/mittwald/kubernetes-replicator
GitHub - mittwald/kubernetes-replicator: Kubernetes controller for synchronizing secrets &...
githubmittwaldkubernetesamp
https://github.blog/developer-skills/github/github-protips-tips-tricks-hacks-and-secrets-from-sarah-vessels/
GitHub Protips: Tips, tricks, hacks, and secrets from Sarah Vessels - The GitHub Blog
May 14, 2021 - In this edition of GitHub Protips, Sarah Vessels shares how she expresses ideas in code and doesn’t stress about the nitty-gritty details of how to neatly...
github protipstricks hacks
https://www.bleepingcomputer.com/news/security/shai-hulud-malware-infects-500-npm-packages-leaks-secrets-on-github/
Shai-Hulud malware infects 500 npm packages, leaks secrets on GitHub
Hundreds of trojanized versions of well-known packages such as Zapier, ENS Domains, PostHog, and Postman have been planted in the npm registry in a new...
shai hulud malwareinfectsnpm
https://www.devclass.com/development/2025/06/18/misconfigured-github-actions-could-leave-repos-and-secrets-exposed-sysdig-finds/101170
Misconfigured GitHub Actions could leave repos and secrets exposed, Sysdig finds
Jun 18, 2025 - Sysdig researchers have warned that developers and maintainers could be leaving their repos open to hijacking through inadequately […]
github actionscould leave
Sponsored https://www.cheekycrush.com/
CheekyCrush
https://github.com/stakater/Reloader
GitHub - stakater/Reloader: A Kubernetes controller to watch changes in ConfigMap and Secrets and...
A Kubernetes controller to watch changes in ConfigMap and Secrets and do rolling upgrades on Pods with their associated Deployment, StatefulSet, DaemonSet and...
kubernetes controllergithub
https://www.bleepingcomputer.com/news/security/github-expands-security-tools-after-39-million-secrets-leaked-in-2024/
GitHub expands security tools after 39 million secrets leaked in 2024
Over 39 million secrets like API keys and account credentials were leaked on GitHub throughout 2024, exposing organizations and users to significant security...
github expandssecurity tools