Skip to content

GitHub security workshop: Add a safe secret scanning and push protection lab #275

Description

@softchris

Goal

Let learners experience a blocked push and the secret alert workflow without creating or publishing a usable credential.

Scope

Use only a GitHub-documented, non-sensitive test pattern that is guaranteed to exercise push protection at the time the workshop is validated. The test value must be generated or copied during the exercise and must not be stored in the template history. Cover the blocked push, remediation, bypass governance, alert review, and cleanup.

Acceptance criteria

  • Learners enable or verify secret scanning and push protection using current settings guidance.
  • The exercise links to the authoritative source for an approved non-sensitive test pattern.
  • No token-like test value is committed to this template repository.
  • Learners attempt the demonstration on a disposable branch and observe a blocked push.
  • The exercise explains why inventing an arbitrary fake string may not match a supported pattern.
  • Learners remove the value and successfully push the cleaned commit.
  • Bypass reasons, delegated bypass, alert ownership, and auditability are explained without requiring a bypass.
  • A fallback path is provided when push protection cannot be enabled.
  • Final verification confirms no secret or test pattern remains in branch history.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions