You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hi all — a heads-up about two repository settings we just turned on for zio/zio-http, plus one pull request in flight. One of these changes can affect your pushes, so it's worth two minutes of reading if you contribute code.
What changed
Secret scanning is enabled. GitHub now scans the repository — including its history — for credentials matching known provider patterns (cloud keys, package registry tokens, GitHub tokens, and similar). Maintainers get an alert if one is found. The initial scan of existing history came back clean.
Push protection is enabled. This is the change that can affect you directly. If a commit you push contains something GitHub recognizes as a credential, the push is rejected before it lands on GitHub.
What to do if your push is blocked
The error message will name the file, the line, and the kind of secret detected.
Treat the credential as compromised and rotate it. If it was ever pushed anywhere, or is a real key from any environment, revoke and reissue it. Do this first — it matters more than getting the push through.
Remove it from the commit, not just from the working tree. Amend the commit or rebase so the secret is absent from every commit you're pushing; deleting the line in a follow-up commit leaves it in history and the push stays blocked.
Re-push.
If the detection is a false positive — a dummy value in an example or a test fixture — GitHub's block message includes a link to report it as such and proceed. Please prefer a clearly fake placeholder (secret-goes-here, <your-token>) over anything resembling a real key, and avoid pasting realistic-looking connection strings into examples or docs.
Push protection currently covers provider patterns only. Generic patterns — bare private keys, database connection strings, HTTP auth headers — are not enabled, because this repository legitimately carries many such shapes across the zio-http-example-* modules, the TLS/mTLS tests, and the authentication docs, and we didn't want a wave of false positives landing on contributor pull requests. We may revisit this later; input welcome in the comments.
Reporting a vulnerability
Unrelated to the settings above, a reminder on where security reports go: private vulnerability reporting is enabled on this repository. If you find a security issue in ZIO HTTP, please do not open a public issue, pull request, or Discord message. Use the private form instead:
That opens a private channel with the maintainers so the issue can be fixed before disclosure.
Questions
Ask below. If push protection blocks you on something that is clearly not a secret, mention it here too — that's useful signal for tuning what we enable next.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Hi all — a heads-up about two repository settings we just turned on for
zio/zio-http, plus one pull request in flight. One of these changes can affect your pushes, so it's worth two minutes of reading if you contribute code.What changed
Secret scanning is enabled. GitHub now scans the repository — including its history — for credentials matching known provider patterns (cloud keys, package registry tokens, GitHub tokens, and similar). Maintainers get an alert if one is found. The initial scan of existing history came back clean.
Push protection is enabled. This is the change that can affect you directly. If a commit you push contains something GitHub recognizes as a credential, the push is rejected before it lands on GitHub.
What to do if your push is blocked
The error message will name the file, the line, and the kind of secret detected.
If the detection is a false positive — a dummy value in an example or a test fixture — GitHub's block message includes a link to report it as such and proceed. Please prefer a clearly fake placeholder (
secret-goes-here,<your-token>) over anything resembling a real key, and avoid pasting realistic-looking connection strings into examples or docs.Push protection currently covers provider patterns only. Generic patterns — bare private keys, database connection strings, HTTP auth headers — are not enabled, because this repository legitimately carries many such shapes across the
zio-http-example-*modules, the TLS/mTLS tests, and the authentication docs, and we didn't want a wave of false positives landing on contributor pull requests. We may revisit this later; input welcome in the comments.Reporting a vulnerability
Unrelated to the settings above, a reminder on where security reports go: private vulnerability reporting is enabled on this repository. If you find a security issue in ZIO HTTP, please do not open a public issue, pull request, or Discord message. Use the private form instead:
https://github.com/zio/zio-http/security/advisories/new
That opens a private channel with the maintainers so the issue can be fixed before disclosure.
Questions
Ask below. If push protection blocks you on something that is clearly not a secret, mention it here too — that's useful signal for tuning what we enable next.
All reactions