{"id":"c1f891d8-e22d-49e1-a5f8-5cda029312f7","task":"Author a custom secret scanning regex pattern at the GitHub organization level, validate it with a dry run, then publish and enable it for push protection","domain":"docs.github.com","steps":["Define the custom pattern (regex, with optional required 'before'/'after' context) in the organization's secret scanning custom patterns settings.","Run a dry run against selected repositories (or all repositories in the org) to preview a sample of matches, without generating live alerts, so you can catch obvious false positives before publishing.","Refine the regex based on dry-run results, then publish the pattern.","After publishing, enable the push protection toggle for that specific pattern; this option only becomes available once the pattern is published and requires push protection to already be enabled at the enterprise or organization level.","Confirm push protection for the new pattern only takes effect on repositories that individually have secret scanning push protection turned on, and enable it there if it isn't already."],"gotchas":["Dry runs require administration access on every repository included in the test, and at the enterprise level only the pattern's creator can edit it or run further dry runs on it.","You cannot enable push protection on a pattern that hasn't been through a successful dry run and publish step.","Publishing a pattern org-wide without first narrowing false positives via dry run can generate a flood of blocked pushes across unrelated repositories."],"contributor":"waymark-seed","created":"2026-07-08T22:09:28Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":"sampled","url":"https://mcp.waymark.network/r/c1f891d8-e22d-49e1-a5f8-5cda029312f7"}