SNACK: 3-line summary
- GitHub has added five secret-scanning detectors for Lovable Labs, Pydantic Services Inc. and Supabase.
- The expanded coverage can identify supported keys and tokens left in older commits, not just current files.
- Public repositories are scanned free; organization-owned private and internal repositories need GitHub Secret Protection on an eligible plan.
GitHub’s October 5, 2026 secret scanning update adds five credential detectors for Lovable Labs, Pydantic Services Inc. and Supabase, widening coverage for service keys and tokens accidentally committed to repositories.

Snackgirls react
AIKO: I’d like to compare scans of the same old Git history before and after a new detector is added. Same commits, different things to notice.
Nea: I’d like to maintain a small archive of hobby-game lore and character notes. Service keys are one detail I’d rather keep out of that history.
The five additions, by service
Lovable Labs: lovable_api_key.
Pydantic Services Inc.: logfire_token and pydantic_ai_gateway_api_key.
Supabase: supabase_oauth_access_token and supabase_scoped_personal_access_token.

When GitHub notifies Lovable directly
Lovable Labs has also joined the secret scanning partnership program. When GitHub finds a Lovable partner secret in a public repository, it forwards the credential to Lovable so the company can revoke or rotate it.
Partner reports go directly to the issuer and do not appear in the repository’s secret scanning alerts. User secrets follow a different route: they generate repository alerts in public or private repositories where the feature is available.
Public repositories are scanned automatically for free. Organization-owned private and internal repositories require GitHub Secret Protection to be enabled on GitHub Team or GitHub Enterprise Cloud.

Find the alert—and replace the exposed credential
Repository owners, organization owners, security managers and users with the admin role can view alerts under Security and quality → Vulnerability alerts → Secret scanning. The provider and secret-type filters can help narrow the list.
Secret scanning covers Git history across all branches. GitHub also periodically rescans repositories when new secret types are added, so its scope extends to credentials left in older commits.
If you find an exposed credential, revoke or rotate it promptly. Removing it from the current file does not invalidate the key or token.
Sources and checked date: October 6, 2026

Comments
0No login needed. Edit or delete your comment from the same browser.
All comments 0
한국어 · English · 日本語No comments yet. Start the conversation.