This question is referring to user-facing repository alerts for partner secrets. When GitHub detects authentication credentials belonging to a participating service provider in public content, GitHub can send a partner alert directly to that provider. Partner alerts are not displayed as normal repository secret-scanning alerts to repository administrators. The provider can then validate, revoke, or otherwise remediate the exposed credential. By contrast, newly committed secrets are precisely what secret scanning is designed to detect, changing repository visibility does not suppress scanning, and a revoked credential can still be detected even though validity information may indicate that it is inactive. Thus, interpreted in the context of repository-user reporting, A is the correct answer: supported partner credentials can be reported directly to the issuing provider rather than surfaced as a normal user alert.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit