# Scanning Before You Push — 1Password and Secrets Hygiene for Developers

Source: https://www.geekswithgeeks.com/en/secrets-hygiene/leak-scanning

> Use pre-commit scanning and platform push protection to block secrets.

## Two safety nets

A local scanner such as gitleaks checks staged changes before a commit is made. GitHub secret scanning with push protection checks pushes on the server side and can block known token formats. Use both; neither catches every kind of secret.

## Catch early, respond fast

Scanners catch many mistakes before they are pushed. When one slips through, speed matters more than perfection.

![Four stages: prevent, detect, revoke, clean up.](assets/figures/secrets-hygiene/section-7-map.svg) — Figure 7.1 — Prevent, detect, revoke and clean up.

## A pre-commit hook

Install gitleaks, then add a hook file that scans only the staged changes and stops the commit if it finds something.

```bash
# .git/hooks/pre-commit  (make it executable with chmod +x)
#!/bin/sh
gitleaks protect --staged --redact -v
```

## Expect false alarms

Scanners sometimes flag harmless strings. Tune them with an allowlist for known fake values, but never disable the scan for real folders just to silence it.

**Quiz:** What does push protection do?

- [ ] Encrypts your repository
- [x] Blocks a push that contains a detected secret
- [ ] Deletes old branches
- [ ] Speeds up git clone

*Answer:* Blocks a push that contains a detected secret. It checks the pushed content for known secret patterns and rejects the push before it lands.
