{"id":98757,"date":"2026-09-09T10:14:02","date_gmt":"2026-09-09T17:14:02","guid":{"rendered":"https:\/\/github.blog\/changelog\/2026-09-09-block-pull-requests-with-exposed-secrets-from-merging"},"modified":"2026-09-15T12:43:32","modified_gmt":"2026-09-15T19:43:32","slug":"block-pull-requests-with-exposed-secrets-from-merging","status":"publish","type":[3522],"link":"https:\/\/github.blog\/changelog\/2026-09-09-block-pull-requests-with-exposed-secrets-from-merging","title":{"rendered":"Block pull requests with exposed secrets from merging"},"content":{"rendered":"<!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body><p>Repository rulesets allow you to easily add scalable protections across your repositories. Starting today, you can use repository rulesets to block pull requests from merging when the pull request introduces secret scanning alerts.<\/p>\n<h3 id=\"whats-new\" id=\"whats-new\" ><a class=\"heading-link\" href=\"#whats-new\">What&rsquo;s new<span class=\"heading-hash pl-2 text-italic text-bold\" aria-hidden=\"true\"><\/span><\/a><\/h3>\n<p>You can enable the new rule <strong>require secret scanning alerts are resolved<\/strong> on pull requests for selected repositories. Developers without bypass permissions must clear the block by resolving each alert.<\/p>\n<p>The rule checks two things before a pull request can merge:<\/p>\n<ul>\n<li>A secret scan has completed for the head commit<\/li>\n<li>No alerts are open for secrets introduced by the pull request&rsquo;s commits<\/li>\n<\/ul>\n<p>By default, the rule runs on open pull requests and blocks secrets found via provider patterns. You can additionally configure the rule to block other categories (e.g., custom or generic patterns).<\/p>\n<p>This rule is available today in public preview for customers with GitHub Secret Protection or GitHub Advanced Security.<\/p>\n<h2 id=\"how-this-rule-differs-from-push-protection\" id=\"how-this-rule-differs-from-push-protection\" ><a class=\"heading-link\" href=\"#how-this-rule-differs-from-push-protection\">How this rule differs from push protection<span class=\"heading-hash pl-2 text-italic text-bold\" aria-hidden=\"true\"><\/span><\/a><\/h2>\n<p>Push protection stops a secret at the push, before it ever reaches the repository. This rule adds an additional layer of protection at the pull request layer, catching cases that push protection isn&rsquo;t able to or configured to catch. For example, you may keep push protection disabled for generic pattern secret types, while keeping a ruleset to block pull requests for those secret types.<\/p>\n<h2 id=\"how-to-configure-the-rule\" id=\"how-to-configure-the-rule\" ><a class=\"heading-link\" href=\"#how-to-configure-the-rule\">How to configure the rule<span class=\"heading-hash pl-2 text-italic text-bold\" aria-hidden=\"true\"><\/span><\/a><\/h2>\n<ol>\n<li>In your repository, organization, or enterprise settings, go to the <strong>Repository &gt; Rulesets<\/strong> tab.<\/li>\n<li>Create or edit a ruleset targeting the branches you want to protect.<\/li>\n<li>Select <strong>Require secret scanning alerts are resolved<\/strong>.<\/li>\n<\/ol>\n<p>You can also configure the rule through the REST API using the <code>require_secret_scanning_alert_resolution<\/code> rule type with a <code>secret_types<\/code> parameter, or through GraphQL as <code>REQUIRE_SECRET_SCANNING_ALERT_RESOLUTION<\/code>.<\/p>\n<h2 id=\"learn-more\" id=\"learn-more\" ><a class=\"heading-link\" href=\"#learn-more\">Learn more<span class=\"heading-hash pl-2 text-italic text-bold\" aria-hidden=\"true\"><\/span><\/a><\/h2>\n<p>Learn more about <a href=\"https:\/\/docs.github.com\/code-security\/secret-scanning\/introduction\/about-secret-scanning\">secret scanning<\/a> and <a href=\"https:\/\/docs.github.com\/enterprise-cloud@latest\/code-security\/concepts\/secret-security\/about-push-protection\">push protection<\/a> in our documentation.<\/p>\n<p>See the <a href=\"https:\/\/docs.github.com\/repositories\/configuring-branches-and-merges-in-your-repository\/managing-rulesets\/about-rulesets\">rulesets documentation<\/a> for how rules are applied and bypassed.<\/p>\n<\/body><\/html>\n","protected":false},"excerpt":{"rendered":"<p>Repository rulesets allow you to easily add scalable protections across your repositories. Starting today, you can use repository rulesets to block pull requests from merging when the pull request introduces&hellip;<\/p>\n","protected":false},"author":2106,"featured_media":0,"template":"","meta":{"_gh_post_show_toc":"","_gh_post_is_no_robots":"","_gh_post_is_featured":"","_gh_post_is_excluded":"","_gh_post_is_unlisted":"","_gh_post_related_link_1":"","_gh_post_related_link_2":"","_gh_post_related_link_3":"","_gh_post_sq_img":"","_gh_post_sq_img_id":"","_gh_post_cta_title":"","_gh_post_cta_text":"","_gh_post_cta_link":"","_gh_post_cta_button":"","_gh_post_recirc_hide":"","_gh_post_recirc_col_1":"","_gh_post_recirc_col_2":"","_gh_post_recirc_col_3":"","_gh_post_recirc_col_4":"","_featured_video":"","_gh_post_additional_query_params":"","footnotes":"","_links_to":"","_links_to_target":"","primary_cta":"","primary_cta_url":"","secondary_cta":"","secondary_cta_url":""},"label":[3627,3628],"group":[3918],"coauthors":[3100],"class_list":["post-98757","changelog","type-changelog","status-publish","hentry","changelog-type-improvements","changelog-label-application-security","changelog-label-platform-governance","changelog-group-09-2026"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.4 (Yoast SEO v28.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Block pull requests with exposed secrets from merging - GitHub Changelog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/github.blog\/changelog\/2026-09-09-block-pull-requests-with-exposed-secrets-from-merging\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Block pull requests with exposed secrets from merging \u00b7 GitHub Changelog\" \/>\n<meta property=\"og:description\" content=\"Repository rulesets allow you to easily add scalable protections across your repositories. Starting today, you can use repository rulesets to block pull requests from merging when the pull request introduces&hellip;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/github.blog\/changelog\/2026-09-09-block-pull-requests-with-exposed-secrets-from-merging\/\" \/>\n<meta property=\"og:site_name\" content=\"The GitHub Blog\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-15T19:43:32+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/github.blog\/wp-content\/uploads\/2026\/09\/Changelog_Improvement_Unfurl_TextOnly_BlockPullRequests.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"2 minutes\" \/>\n\t<meta name=\"twitter:label2\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data2\" content=\"Allison\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/github.blog\\\/changelog\\\/2026-09-09-block-pull-requests-with-exposed-secrets-from-merging\\\/\",\"url\":\"https:\\\/\\\/github.blog\\\/changelog\\\/2026-09-09-block-pull-requests-with-exposed-secrets-from-merging\\\/\",\"name\":\"Block pull requests with exposed secrets from merging - The GitHub Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/github.blog\\\/#website\"},\"datePublished\":\"2026-09-09T17:14:02+00:00\",\"dateModified\":\"2026-09-15T19:43:32+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/github.blog\\\/changelog\\\/2026-09-09-block-pull-requests-with-exposed-secrets-from-merging\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/github.blog\\\/changelog\\\/2026-09-09-block-pull-requests-with-exposed-secrets-from-merging\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/github.blog\\\/changelog\\\/2026-09-09-block-pull-requests-with-exposed-secrets-from-merging\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/github.blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Changelogs\",\"item\":\"https:\\\/\\\/github.blog\\\/changelog\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Block pull requests with exposed secrets from merging\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/github.blog\\\/#website\",\"url\":\"https:\\\/\\\/github.blog\\\/\",\"name\":\"The GitHub Blog\",\"description\":\"Updates, ideas, and inspiration from GitHub to help developers build and design software.\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/github.blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Block pull requests with exposed secrets from merging - GitHub Changelog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/github.blog\/changelog\/2026-09-09-block-pull-requests-with-exposed-secrets-from-merging\/","og_locale":"en_US","og_type":"article","og_title":"Block pull requests with exposed secrets from merging \u00b7 GitHub Changelog","og_description":"Repository rulesets allow you to easily add scalable protections across your repositories. Starting today, you can use repository rulesets to block pull requests from merging when the pull request introduces&hellip;","og_url":"https:\/\/github.blog\/changelog\/2026-09-09-block-pull-requests-with-exposed-secrets-from-merging\/","og_site_name":"The GitHub Blog","article_modified_time":"2026-09-15T19:43:32+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/github.blog\/wp-content\/uploads\/2026\/09\/Changelog_Improvement_Unfurl_TextOnly_BlockPullRequests.jpg","type":"image\/png"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"2 minutes","Written by":"Allison"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/github.blog\/changelog\/2026-09-09-block-pull-requests-with-exposed-secrets-from-merging\/","url":"https:\/\/github.blog\/changelog\/2026-09-09-block-pull-requests-with-exposed-secrets-from-merging\/","name":"Block pull requests with exposed secrets from merging - The GitHub Blog","isPartOf":{"@id":"https:\/\/github.blog\/#website"},"datePublished":"2026-09-09T17:14:02+00:00","dateModified":"2026-09-15T19:43:32+00:00","breadcrumb":{"@id":"https:\/\/github.blog\/changelog\/2026-09-09-block-pull-requests-with-exposed-secrets-from-merging\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/github.blog\/changelog\/2026-09-09-block-pull-requests-with-exposed-secrets-from-merging\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/github.blog\/changelog\/2026-09-09-block-pull-requests-with-exposed-secrets-from-merging\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/github.blog\/"},{"@type":"ListItem","position":2,"name":"Changelogs","item":"https:\/\/github.blog\/changelog\/"},{"@type":"ListItem","position":3,"name":"Block pull requests with exposed secrets from merging"}]},{"@type":"WebSite","@id":"https:\/\/github.blog\/#website","url":"https:\/\/github.blog\/","name":"The GitHub Blog","description":"Updates, ideas, and inspiration from GitHub to help developers build and design software.","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/github.blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/changelogs\/98757","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/changelogs"}],"about":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/types\/changelog"}],"author":[{"embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/users\/2106"}],"version-history":[{"count":1,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/changelogs\/98757\/revisions"}],"predecessor-version":[{"id":98759,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/changelogs\/98757\/revisions\/98759"}],"wp:attachment":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/media?parent=98757"}],"wp:term":[{"taxonomy":"changelog-type","embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/type?post=98757"},{"taxonomy":"changelog-label","embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/label?post=98757"},{"taxonomy":"changelog-group","embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/group?post=98757"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/coauthors?post=98757"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}