Block pull requests with exposed secrets from merging
PreviewVerifiedAdded Sep 22, 2026
Repository rulesets allow you to easily add scalable protections across your repositories. Starting today, you can use repository rulesets to block pull requests from merging when the pull request introduces secret scanning alerts. What’s new You can enable the new rule require secret scanning alerts are resolved on pull requests for selected repositories.
Topics: Security
Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.
More GitHub Advanced Security releases
Every GitHub Advanced Security release| Date | Release | Type |
|---|---|---|
| Sep 9 | npm extends recovery-code security holds to all accounts Update | Update |
| Sep 9 | CodeQL 2.27.0 adds support for Linux ARM64 Update | Update |
| Sep 9 | GitHub Advanced Security expands trial availability Update | Update |
| Sep 9 | Remediate Code Quality findings with agentic autofix Update | Update |
| Sep 10 | AI Scan for pull request APIs in public preview Preview | Preview |
| Sep 8 | Automatic Dependabot access to GitHub-hosted registries Update | Update |
| Sep 15 | Enforce GitHub Advanced Security configurations Update | Update |
| Sep 3 | Multiple trusted publishing configurations for npm GA | GA |