Skip to main content

このバージョンの GitHub Enterprise サーバーはこの日付をもって終了となりました: 2026-04-23. 重大なセキュリティの問題に対してであっても、パッチリリースは作成されません。 パフォーマンスの向上、セキュリティの向上、新機能の向上を図るために、最新バージョンの GitHub Enterprise サーバーにアップグレードしてください。 アップグレードに関するヘルプについては、GitHub Enterprise サポートにお問い合わせください。

サポートされているシークレット スキャン パターン

サポートされているシークレットと、誤ってコミットされたシークレットの不正使用を防ぐために GitHub が連携するパートナーの一覧。

この機能を使用できるユーザーについて

Secret scanning は、次のリポジトリの種類で使用できます。

  • パブリック リポジトリ: Secret scanning は無料で自動的に実行されます。
  • 組織所有のプライベートリポジトリと内部リポジトリ: GitHub Advanced Security または GitHub Team で有効になっている GitHub Enterprise Cloud で使用できます。
  • ユーザー所有のリポジトリ: GitHub Enterprise Cloud および Enterprise Managed Users で利用可能です。 GitHub Enterprise Server で使用できるのは、エンタープライズで GitHub Advanced Security が有効になっている場合です。

secret scanning パターンについて

三、シークレット スキャンニング アラート二つの種類があります。


          シークレット スキャンニング アラート:** リポジトリでサポートされているシークレットが検出されると、リポジトリの [ **<svg version="1.1" width="16" height="16" viewBox="0 0 16 16" class="octicon octicon-shield" aria-label="shield" role="img"><path d="M7.467.133a1.748 1.748 0 0 1 1.066 0l5.25 1.68A1.75 1.75 0 0 1 15 3.48V7c0 1.566-.32 3.182-1.303 4.682-.983 1.498-2.585 2.813-5.032 3.855a1.697 1.697 0 0 1-1.33 0c-2.447-1.042-4.049-2.357-5.032-3.855C1.32 10.182 1 8.566 1 7V3.48a1.75 1.75 0 0 1 1.217-1.667Zm.61 1.429a.25.25 0 0 0-.153 0l-5.25 1.68a.25.25 0 0 0-.174.238V7c0 1.358.275 2.666 1.057 3.86.784 1.194 2.121 2.34 4.366 3.297a.196.196 0 0 0 .154 0c2.245-.956 3.582-2.104 4.366-3.298C13.225 9.666 13.5 8.36 13.5 7V3.48a.251.251 0 0 0-.174-.237l-5.25-1.68ZM8.75 4.75v3a.75.75 0 0 1-1.5 0v-3a.75.75 0 0 1 1.5 0ZM9 10.5a1 1 0 1 1-2 0 1 1 0 0 1 2 0Z"></path></svg> Security** ] タブでユーザーに報告されます。
  • プッシュ保護アラート: 共同作成者がプッシュ保護をバイパスすると、リポジトリの [ Security ] タブでユーザーに報告されます。

各アラート タイプの詳細については、「シークレット スキャン アラートについて」を参照してください。

サポートされているすべてのパターンの詳細については、以下の「サポートされているシークレット」セクションを参照してください。

secret scanning で REST API を使用する場合、Secret type を利用して特定の発行元からのシークレットを報告できます。 詳しくは、「シークレット スキャン用の REST API エンドポイント」をご覧ください。

secret scanning でリポジトリにコミットされたシークレットを検出する必要があると思われ、そうでない場合は、まず GitHub でシークレットがサポートされていることを確認する必要があります。 詳細については、以下のセクションを参照してください。 より高度なトラブルシューティング情報については、「シークレット スキャン検出スコープ」を参照してください。

サポートされているシークレット

次の表では、シークレット タイプごとに secret scanning でサポートされているシークレットを示しています。 テーブル内の情報には、次のデータが含まれる場合があります。

  • Provider: トークン プロバイダーの名前。
  • Secret scanning アラート: GitHub のユーザーにリークが報告されるトークン。
    • GitHub Advanced Security と secret scanning が有効なプライベート リポジトリに適用されます。
    • サポートされているパターンや指定されたカスタム パターンに関連する high confidence のトークン に加え、偽陽性率が高い傾向にある非プロバイダー系トークン (プライベート キーなど) も含まれます。
  • Push protection: GitHub のユーザーにリークが報告されるトークン。 secret scanning とプッシュ保護が有効なリポジトリに適用されます。
  • Validity check: 有効性チェックが実装されているトークン。 現時点では、GitHub トークンにのみ適用されます。
  • メタデータ チェック: 拡張メタデータを使用できるトークン。検出されたシークレットに関する追加のコンテキストを提供します。
  • Base64: Base64 でエンコードされたバージョンがサポートされているトークン。

プロバイダー以外のパターン

メモ

プロバイダー以外のパターンの検出は現在 ベータ 段階であり、変更される可能性があります。

精度レベルは、パターンの種類の一般的な誤検知率に基づいて推定されます。

プロバイダートークンDescription精度
ジェネリックhttp_basic_authentication_header要求ヘッダーの HTTP 基本認証資格情報ミディアム
ジェネリックhttp_bearer_authentication_headerAPI 認証に使用される HTTP ベアラー トークンミディアム
ジェネリックmongodb_connection_string資格情報を含む MongoDB データベースの接続文字列High
ジェネリックmysql_connection_url資格情報を含む MySQL データベースの接続文字列High
ジェネリックopenssh_private_keySSH 認証に使用される OpenSSH 形式の秘密キーHigh
ジェネリックpgp_private_key暗号化と署名に使用される PGP (Pretty Good Privacy) 秘密キーHigh
ジェネリックpostgres_connection_string資格情報を含む PostgreSQL データベースの接続文字列High
ジェネリックrsa_private_key暗号化操作に使用される RSA 秘密キーHigh

メモ

プロバイダー以外のパターンでは、有効性チェックは サポートされていません 。

信頼度の高いパターン

プロバイダートークンSecret scanning アラートプッシュ保護有効性チェックBase64
Adafruitadafruit_io_key✓✓✗✗
Adobeadobe_client_secret✓✓✗✗
Adobeadobe_device_token✓✓✗✗
Adobeadobe_pac_token✓✓✗✗
Adobeadobe_refresh_token✓✓✗✗
Adobeadobe_service_token✓✓✗✗
Adobeadobe_short_lived_access_token✓✓✗✗
Aivenaiven_auth_token✓✓✗✗
Aivenaiven_service_password✓✓✗✗
Alibabaalibaba_cloud_access_key_id
alibaba_cloud_access_key_secret
✓✓✗✗
Amazon AWSaws_access_key_id
aws_secret_access_key
✓✓✗✗
Amazon AWSaws_secret_access_key
aws_session_token
aws_temporary_access_key_id
✓✓✗✗
Anthropicanthropic_api_key✓✓✗✗
Anthropicanthropic_session_id✓✓✗✗
Asanaasana_legacy_format_personal_access_token✓✗✗✗
Asanaasana_personal_access_token✓✓✗✗
Atlassianatlassian_api_token
Token versions
✓✓✗✗
Atlassianatlassian_jwt✓✗✗✗
Authressauthress_service_client_access_key✓✓✗✗
Azureazure_active_directory_application_secret
Token versions
✓✓✗✗
Azureazure_active_directory_user_credential✓✗✗✗
Azureazure_apim_direct_management_key✓✓✗✗
Azureazure_apim_gateway_key✓✓✗✗
Azureazure_apim_repository_key✓✓✗✗
Azureazure_apim_subscription_key✓✓✗✗
Azureazure_app_configuration_connection_string✓✗✗✗
Azureazure_batch_key_identifiable✓✓✗✗
Azureazure_cache_for_redis_access_key✓✓✗✗
Azureazure_communication_services_connection_string✓✗✗✗
Azureazure_container_registry_key_identifiable✓✓✗✗
Azureazure_cosmosdb_key_identifiable✓✓✗✗
Azureazure_devops_personal_access_token✓✓✗✗
Azureazure_event_hub_key_identifiable✓✓✗✗
Azureazure_function_key✓✓✗✗
Azureazure_iot_device_connection_string✓✗✗✗
Azureazure_iot_device_key✓✓✗✗
Azureazure_iot_device_provisioning_key✓✓✗✗
Azureazure_iot_hub_connection_string✓✗✗✗
Azureazure_iot_hub_key✓✓✗✗
Azureazure_iot_provisioning_connection_string✓✗✗✗
Azureazure_management_certificate✓✗✗✗
Azureazure_ml_web_service_classic_identifiable_key✓✓✗✗
Azureazure_relay_key_identifiable✓✓✗✗
Azureazure_sas_token✓✗✗✗
Azureazure_search_admin_key✓✓✗✗
Azureazure_search_query_key✓✓✗✗
Azureazure_service_bus_identifiable✓✓✗✗
Azureazure_signalr_connection_string✓✗✗✗
Azureazure_sql_connection_string✓✗✗✗
Azureazure_sql_password✓✓✗✗
Azureazure_storage_account_key
Token versions
✓✓✗✗
Azureazure_web_pub_sub_connection_string✓✗✗✗
Azuremicrosoft_corporate_network_user_credential✓✗✗✗
Baidubaiducloud_api_accesskey✓✓✗✗
Beamerbeamer_api_key✓✗✗✗
Bitbucketbitbucket_server_personal_access_token✓✓✗✗
Canadian Digital Servicecds_canada_notify_api_key✓✓✗✗
Canvacanva_app_secret✓✓✗✗
Canvacanva_connect_api_secret✓✓✗✗
Canvacanva_secret✓✓✗✗
Cashfreecashfree_api_key✓✓✗✗
Checkout.comcheckout_production_secret_key
Token versions
✓✓✗✗
Checkout.comcheckout_test_secret_key
Token versions
✓✗✗✗
Chief Toolschief_tools_token✓✓✗✗
CircleCIcircleci_bot_access_token✓✓✗✗
CircleCIcircleci_personal_access_token✓✓✗✗
CircleCIcircleci_project_access_token✓✓✗✗
CircleCIcircleci_release_integration_token✓✓✗✗
Clojarsclojars_deploy_token✓✓✗✗
CloudBeescodeship_credential✗✗✗✗
Contentfulcontentful_personal_access_token✓✗✗✗
Contributed Systemscontributed_systems_credentials✗✗✗✗
crates.iocratesio_api_token✓✓✗✗
Databricksdatabricks_access_token✓✓✗✗
Datadogdatadog_api_key✗✗✗✗
Datadogdatadog_app_key✗✗✗✗
Defined Networkingdefined_networking_nebula_api_key✓✓✗✗
DevCycledevcycle_client_api_key✓✓✗✗
DevCycledevcycle_mobile_api_key✓✓✗✗
DevCycledevcycle_server_api_key✓✓✗✗
DigitalOceandigitalocean_oauth_token✓✓✗✗
DigitalOceandigitalocean_personal_access_token✓✓✗✗
DigitalOceandigitalocean_refresh_token✓✓✗✗
DigitalOceandigitalocean_system_token✓✓✗✗
Discorddiscord_bot_token
Token versions
✓✓✗✗
Dockerdocker_personal_access_token✓✓✗✗
Dopplerdoppler_audit_token✓✓✗✗
Dopplerdoppler_cli_token✓✓✗✗
Dopplerdoppler_personal_token✓✓✗✗
Dopplerdoppler_scim_token✓✓✗✗
Dopplerdoppler_service_account_token✓✓✗✗
Dopplerdoppler_service_token✓✓✗✗
Dropboxdropbox_access_token✓✗✗✗
Dropboxdropbox_short_lived_access_token✓✓✗✗
Duffelduffel_live_access_token✓✓✗✗
Duffelduffel_test_access_token✓✗✗✗
Dynatracedynatrace_api_token✓✗✗✗
Dynatracedynatrace_internal_token✓✗✗✗
EasyPosteasypost_production_api_key✓✓✗✗
EasyPosteasypost_test_api_key✓✗✗✗
eBayebay_production_client_id
ebay_production_client_secret
✓✗✗✗
eBayebay_sandbox_client_id
ebay_sandbox_client_secret
✓✗✗✗
Facebookfacebook_access_token✓✗✗✗
Fastlyfastly_api_token
Token versions
✓✗✗✗
Figmafigma_pat✓✓✗✗
Finicityfinicity_app_key✓✗✗✗
Firebasefirebase_cloud_messaging_server_key✓✗✗✗
Flutterwaveflutterwave_live_api_secret_key✓✓✗✗
Flutterwaveflutterwave_test_api_secret_key✓✗✗✗
Frame.ioframeio_developer_token✓✗✗✗
Frame.ioframeio_jwt✓✗✗✗
FullStoryfullstory_api_key
Token versions
✓✓✗✗
GitHubgithub_app_installation_access_token
Token versions
✓✓✓✗
GitHubgithub_oauth_access_token
Token versions
✓✓✓✗
GitHubgithub_personal_access_token
Token versions
✓✓✓✗
GitHubgithub_refresh_token✓✓✓✗
GitHubgithub_ssh_private_key✓✓✓✗
GitHubgithub_test_token✓✗✗✗
GitHub Secret Scanningsecret_scanning_sample_token✓✓✗✗
GitLabgitlab_access_token✓✗✗✗
GoCardlessgocardless_live_access_token✓✗✗✗
GoCardlessgocardless_sandbox_access_token✓✗✗✗
Googlegoogle_api_key✓✗✗✗
Googlegoogle_cloud_private_key_id✗✗✗✗
Googlegoogle_cloud_service_account_credentials✓✓✗✗
Googlegoogle_cloud_storage_access_key_secret
google_cloud_storage_service_account_access_key_id
✓✓✗✗
Googlegoogle_cloud_storage_access_key_secret
google_cloud_storage_user_access_key_id
✓✓✗✗
Googlegoogle_oauth_access_token✓✗✗✗
Googlegoogle_oauth_client_id
google_oauth_client_secret
✓✓✗✗
Googlegoogle_oauth_refresh_token✓✗✗✗
Grafanagrafana_cloud_api_key✓✓✗✗
Grafanagrafana_cloud_api_token✓✓✗✗
Grafanagrafana_project_api_key✓✓✗✗
Grafanagrafana_project_service_account_token✓✓✗✗
HashiCorphashicorp_vault_batch_token
Token versions
✓✓✗✗
HashiCorphashicorp_vault_root_service_token✓✓✗✗
HashiCorphashicorp_vault_service_token
Token versions
✓✓✗✗
HashiCorpterraform_api_token✓✓✗✗
Highnotehighnote_rk_live_key✓✓✗✗
Highnotehighnote_rk_test_key✓✓✗✗
Highnotehighnote_sk_live_key✓✓✗✗
Highnotehighnote_sk_test_key✓✓✗✗
HOPhop_bearer✓✓✗✗
HOPhop_pat✓✓✗✗
HOPhop_ptk✓✓✗✗
Hubspothubspot_api_key
Token versions
✓✓✗✗
Hubspothubspot_personal_access_key✓✓✗✗
Hubspothubspot_smtp_credential✗✗✗✗
IBMibm_cloud_iam_key✓✗✗✗
IBMibm_softlayer_api_key✓✗✗✗
Intercomintercom_access_token✓✓✗✗
Ionicionic_personal_access_token
Token versions
✓✓✗✗
Ionicionic_refresh_token
Token versions
✓✓✗✗
JFrogjfrog_platform_access_token✓✓✗✗
JFrogjfrog_platform_api_key✓✓✗✗
JFrogjfrog_platform_reference_token✓✓✗✗
LaunchDarklylaunchdarkly_access_token✗✗✗✗
Lightspeedlightspeed_xs_pat✓✓✗✗
Linearlinear_api_key✓✓✗✗
Linearlinear_oauth_access_token✓✓✗✗
Loblob_live_api_key✓✗✗✗
Loblob_test_api_key✓✗✗✗
Localstacklocalstack_api_key✓✓✗✗
LogicMonitorlogicmonitor_bearer_token✓✓✗✗
LogicMonitorlogicmonitor_lmv1_access_key✓✓✗✗
Login with Amazonamazon_oauth_client_id
amazon_oauth_client_secret
amazon_oauth_client_secret
✓✓✗✗
Mailchimpmailchimp_api_key✓✗✗✗
Mailchimpmandrill_api_key✗✗✗✗
Mailgunmailgun_api_key
Token versions
✓✗✗✗
Mailgunmailgun_smtp_credential✗✗✗✗
Mapboxmapbox_secret_access_token✓✗✗✗
MaxMindmaxmind_license_key✓✓✗✗
Mercurymercury_non_production_api_token✓✓✗✗
Mercurymercury_production_api_token✓✓✗✗
Mergifymergify_application_key✓✓✗✗
MessageBirdmessagebird_api_key✓✗✗✗
Midtransmidtrans_production_server_key✓✓✗✗
Midtransmidtrans_sandbox_server_key✓✗✗✗
New Relicnew_relic_insights_query_key✓✓✗✗
New Relicnew_relic_license_key✓✗✗✗
New Relicnew_relic_personal_api_key✓✓✗✗
New Relicnew_relic_rest_api_key✓✓✗✗
Notionnotion_integration_token✓✗✗✗
Notionnotion_oauth_client_secret✓✗✗✗
npmnpm_access_token
Token versions
✓✓✗✗
NuGetnuget_api_key✓✓✗✗
Octopus Deployoctopus_deploy_api_key✓✗✗✗
Oculusoculus_access_token✓✗✗✗
OneChronosonechronos_api_key✓✓✗✗
OneChronosonechronos_eb_api_key✓✓✗✗
OneChronosonechronos_eb_encryption_key✓✓✗✗
OneChronosonechronos_oauth_token✓✓✗✗
OneChronosonechronos_refresh_token✓✓✗✗
Onfidoonfido_live_api_token✓✓✗✗
Onfidoonfido_sandbox_api_token✓✗✗✗
OpenAIopenai_api_key
Token versions
✓✓✗✗
Orbitorbit_api_token✓✗✗✗
PagerDutypagerduty_oauth_secret✓✓✗✗
PagerDutypagerduty_oauth_token✓✓✗✗
Palantirpalantir_jwt✓✓✗✗
Persona Identitiespersona_production_api_key✓✓✗✗
Persona Identitiespersona_sandbox_api_key✓✓✗✗
Pinterestpinterest_access_token✓✓✗✗
Pinterestpinterest_refresh_token✓✓✗✗
PlanetScaleplanetscale_database_password✓✓✗✗
PlanetScaleplanetscale_oauth_token✓✓✗✗
PlanetScaleplanetscale_service_token✓✓✗✗
Plivoplivo_auth_id
plivo_auth_token
✓✓✗✗
Postmanpostman_api_key✓✓✗✗
Postmanpostman_collection_key✓✓✗✗
Prefectprefect_server_api_key✓✓✗✗
Prefectprefect_user_api_key✓✓✗✗
Proctorioproctorio_consumer_key✓✗✗✗
Proctorioproctorio_linkage_key✓✗✗✗
Proctorioproctorio_registration_key✓✗✗✗
Proctorioproctorio_secret_key
Token versions
✓✓✗✗
Pulumipulumi_access_token✓✗✗✗
PyPIpypi_api_token✓✗✗✗
ReadMereadmeio_api_access_token✓✓✗✗
redirect.pizzaredirect_pizza_api_token✓✓✗✗
Replicatereplicate_api_token✗✗✗✗
Rootlyrootly_api_key✓✓✗✗
RubyGemsrubygems_api_key✓✗✗✗
Samsarasamsara_api_token✓✓✗✗
Samsarasamsara_oauth_access_token✓✓✗✗
Segmentsegment_public_api_token✓✓✗✗
SendGridsendgrid_api_key✓✓✗✗
Sendinbluesendinblue_api_key✓✓✗✗
Sendinbluesendinblue_smtp_key✓✓✗✗
Shipposhippo_live_api_token✓✓✗✗
Shipposhippo_test_api_token✓✗✗✗
Shopifyshopify_access_token✓✓✗✗
Shopifyshopify_app_client_credentials✓✗✗✗
Shopifyshopify_app_client_secret✓✗✗✗
Shopifyshopify_app_shared_secret✓✓✗✗
Shopifyshopify_custom_app_access_token✓✗✗✗
Shopifyshopify_marketplace_token✓✗✗✗
Shopifyshopify_merchant_token✓✗✗✗
Shopifyshopify_partner_api_token✓✗✗✗
Shopifyshopify_private_app_password✓✗✗✗
Slackslack_api_token
Token versions
✓✓✗✗
Slackslack_incoming_webhook_url✓✗✗✗
Slackslack_workflow_webhook_url✓✗✗✗
Squaresquare_access_token
Token versions
✓✗✗✗
Squaresquare_production_application_secret✓✗✗✗
Squaresquare_sandbox_application_secret✓✗✗✗
SSLMatesslmate_api_key
Token versions
✓✗✗✗
SSLMatesslmate_cluster_secret✓✗✗✗
Stripestripe_api_key✓✓✗✗
Stripestripe_legacy_api_key✓✗✗✗
Stripestripe_live_restricted_key✓✗✗✗
Stripestripe_test_restricted_key✓✗✗✗
Stripestripe_test_secret_key✓✗✗✗
Stripestripe_webhook_signing_secret✓✗✗✗
Supabasesupabase_service_key
Token versions
✓✗✗✗
Tableautableau_personal_access_token✓✗✗✗
Telegramtelegram_bot_token✓✗✗✗
Telnyxtelnyx_api_v2_key✓✓✗✗
Tencenttencent_cloud_secret_id✓✓✗✗
Tencenttencent_wechat_api_app_id✓✗✗✗
Twiliotwilio_access_token✓✓✗✗
Twiliotwilio_account_sid✓✓✗✗
Twiliotwilio_api_key✓✓✗✗
Typeformtypeform_personal_access_token✓✓✗✗
Uniwisewiseflow_api_key✓✓✗✗
Unkeyunkey_root_key✓✗✗✗
VolcEnginevolcengine_access_key_id✓✓✗✗
Wakatimewakatime_api_key✓✓✗✗
Wakatimewakatime_app_secret✓✓✗✗
Wakatimewakatime_oauth_access_token✓✓✗✗
Wakatimewakatime_oauth_refresh_token✓✓✗✗
Workatoworkato_developer_api_token
Token versions
✓✓✗✗
WorkOSworkos_production_api_key
Token versions
✓✓✗✗
WorkOSworkos_staging_api_key
Token versions
✓✗✗✗
Yandexyandex_cloud_api_key✓✗✗✗
Yandexyandex_cloud_iam_access_secret✓✗✗✗
Yandexyandex_cloud_iam_cookie✓✗✗✗
Yandexyandex_cloud_iam_token✓✗✗✗
Yandexyandex_cloud_smartcaptcha_server_key✓✓✗✗
Yandexyandex_dictionary_api_key✓✗✗✗
Yandexyandex_passport_oauth_token✓✓✗✗
Yandexyandex_predictor_api_key✓✗✗✗
Yandexyandex_translate_api_key✓✗✗✗
Zuplozuplo_consumer_api_key✓✓✗✗

トークンのバージョン

サービス プロバイダーは、トークンの生成に使用されるパターンを定期的に更新しており、複数のバージョンのトークンをサポートしている場合があります。 プッシュ保護は、secret scanning が確実に識別できる最新のトークン バージョンのみをサポートしています。 これにより、レガシー トークンで発生しやすい偽陽性の結果により、プッシュ保護が不必要にコミットをブロックするのを回避できます。

詳細については、次を参照してください。