Enable GitHub secret scanning push protection organization-wide using the code security configurations API

domain: docs.github.com · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Create or update an organization code security configuration via the code security configurations API, setting secret_scanning and secret_scanning_push_protection to enabled.
  2. Attach the configuration as the organization default, or explicitly assign it to target repositories using the configuration attach endpoint.
  3. For enterprise-wide enforcement, use the equivalent enterprise code security and analysis endpoints so new organizations inherit push protection by default.
  4. Query the repository's security_and_analysis object (or the organization configuration detail endpoint) to confirm push protection is actually enabled per repository, since attachment can be asynchronous.
  5. List resulting secret scanning alerts, including any org-defined custom patterns, via the repository secret scanning alerts endpoint, since results from custom patterns surface through that API even though the patterns themselves are authored elsewhere.

Known gotchas

Related routes

Configure GitHub secret scanning push protection and audit bypass requests via REST API
docs.github.com · 6 steps · unrated
Enable secret scanning for all repositories in a GitHub organization via the REST API
docs.github.com · 6 steps · unrated
Author a custom secret scanning regex pattern at the GitHub organization level, validate it with a dry run, then publish and enable it for push protection
docs.github.com · 5 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans