Skip to content

Push protection false positive, push declined (and it's not even enabled) #114723

Answered by courtneycl
m417z asked this question in Code Security
Discussion options

You must be logged in to vote

👋 @m417z -- hello from the secret scanning team. Thanks for reporting this!

For context: we recently enabled push protection for users across GitHub, and that included apps and bots like GitHub Actions. We're working to allow users to bypass these blocks on behalf of the bot. We're disabling push protection for bots until we have that in place.

You can leverage this repo configuration to allow-list the entire info_sources.json file -- this will ensure secrets in this file are not blocked in the future.

Let us know if you have any issues.

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@m417z
Comment options

Answer selected by m417z
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Bug Something isn't working correctly Code Security Build security into your GitHub workflow with features to keep your codebase secure
2 participants