Aller au contenu principal

Monitored public sources

GitGuardian Public Monitoring continuously scans public GitHub for exposed secrets related to your organization. It is now expanding beyond GitHub to cover additional public sources, starting with DockerHub.

Each source is described by the same four characteristics:

  • What we scan - the type of public content we analyze on that source (for example, commits or container image layers).
  • Scan model - how the source is covered over time:
    • Real-time: new content is scanned as it is published.
    • Historical: existing public content is scanned, as opposed to new content as it appears.
  • Attachment reasons - the rules that attach a detected secret to your company. Each source supports a subset of these rules, depending on the data it exposes. See Company public perimeter for how attachment works.
  • Availability - whether the source is generally available or in limited availability.

Supported sources

SourceWhat we scanScan modelAttachment reasonsAvailability
GitHub - CommitsPublic commitsReal-time + historicalDeveloper · Organization · Secret grasperGenerally available
GitHub - GistsPublic gistsHistorical onlyDeveloperGenerally available
DockerHub - Image layersPublic image layersHistorical onlySecret grasper · Domain in secret value · Domain in owner profileLimited availability

For the specifics of each source, see:

Limited availability

Sources marked as Limited availability are currently enabled for selected workspaces. Contact your account team to request access.