Many users praised GitHub's clearance of 20,000 secret scanning alerts as an impressive achievement, while others criticized unrelated outages like GitHub Actions and questioned whether the alerts were just mass-dismissed false positives.
Based on 9 visible X reactions from 13 accounts; directional sample.
Ask a question below.
Published answers will appear here.
@github Impressive achievement by the GitHub team! 👏 How did the shared responsibility model across engineering actually play out in practice—did it shift any cultural habits around secret management? Would love to hear what worked best for other orgs tackling similar alert fatigue.
@github Hey assholes, GitHub actions is still down. Stop making X posts and get your pipeline working again. What are we paying you for? Your 99.99% uptime is looking like 80% uptime. When will it be 50%?
@github Finding repo owners is the real boss fight. Usually 'shared responsibility' means everyone ignores the alert until it blocks a Friday deploy.
@github Parabéns ❤️ ❤️ ❤️
The key was separating noise from real risk, validating active credentials, finding owners, and making remediation a shared responsibility across engineering.
20,000+ secret scanning alerts across 15,000 repos. Nine months later, GitHub reached inbox zero.
Many users praised GitHub's clearance of 20,000 secret scanning alerts as an impressive achievement, while others criticized unrelated outages like GitHub Actions and questioned whether the alerts were just mass-dismissed false positives.
Based on 9 visible X reactions from 13 accounts; directional sample.
Ask a question below.
Published answers will appear here.