Truffle Security's research revealed that more than 543,000 valid credentials were publicly exposed in GitHub repositories as of July. These credentials remained active despite GitHub's security measures. The data was gathered by scanning 224 million repositories and over 58 billion files, showing a median exposure time of 784 days for unique credentials. Some credentials were over 6.3 years old, with the oldest dating back to 2009.
The number of exposed credentials on GitHub is more than double what Truffle Security found on Hugging Face, where 221,303 working credentials were detected in August. The research also indicates an increasing trend in secret density over time, with working credentials rising from 3.72 per million files in 2015 to a peak of 11.62 in 2025.
GitHub introduced Push Protection in April 2022 for Advanced Security users, expanding it to public repositories in May 2023 and enabling it by default a year later. This feature scans incoming code for secret patterns and blocks uploads if detected. However, it does not revoke previously exposed credentials. Truffle Security reported that 199,843 of the identified credentials were exposed after Push Protection was activated for all users in February 2024, representing about 36.8% of the total. Additionally, 51.8% of the live credentials fell into categories not blocked by GitHub's default Push Protection, such as database connection strings and Google API keys. Despite these limitations, Push Protection reduced the rate of exposed credentials in covered categories by 53% after its default activation.
The study also observed varying rates of credential revocation depending on the service. For instance, out of 101,886 committed npm tokens, only one remained active. This contrasts with other credential types, indicating that some services are more proactive or efficient in revoking leaked secrets than others.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Truffle Security identified 543,699 active credentials exposed in public GitHub repositories, despite GitHub's secret scanning and push protection features. This exposure highlights a gap in credential revocation processes by providers, as many of these secrets remain valid years after being committed.
A study by Truffle Security found over 543,000 valid credentials exposed in public GitHub repositories, with some remaining accessible for years. This highlights that GitHub's Push Protection, while effective for new exposures in covered categories, does not revoke existing leaked credentials and misses certain types of secrets.