Lesson 19 / 24
Scanning Before You Push
Use pre-commit scanning and platform push protection to block secrets.
Two safety nets
A local scanner such as gitleaks checks staged changes before a commit is made. GitHub secret scanning with push protection checks pushes on the server side and can block known token formats. Use both; neither catches every kind of secret.
Catch early, respond fast
Scanners catch many mistakes before they are pushed. When one slips through, speed matters more than perfection.
A pre-commit hook
Install gitleaks, then add a hook file that scans only the staged changes and stops the commit if it finds something.
# .git/hooks/pre-commit (make it executable with chmod +x)
#!/bin/sh
gitleaks protect --staged --redact -vExpect false alarms
Scanners sometimes flag harmless strings. Tune them with an allowlist for known fake values, but never disable the scan for real folders just to silence it.
Quick check: What does push protection do?
- Encrypts your repository
- Blocks a push that contains a detected secret
- Deletes old branches
- Speeds up git clone
Answer
Blocks a push that contains a detected secret — It checks the pushed content for known secret patterns and rejects the push before it lands.