机密扫描模式
Advanced Security 会维护多组默认密钥扫描模式:
- *推送保护模式 - 用于在启用了机密扫描推送保护的存储库中检测推送时的潜在机密。
- 用户警报模式 - 用于检测启用了密钥扫描警报的存储库中的潜在密钥。
- 非提供程序模式 - 用于检测启用了密钥扫描警报的存储库中的结构化密钥的常见事件。
支持的机密
部分 | 说明 |
---|---|
提供程序 | 令牌提供程序的名称。 |
令牌名称 | Advanced Security 密钥扫描所发现令牌的类型。 |
用户 | 推送后向用户报告出现泄漏情况的对应令牌。 适用于启用高级安全性的所有存储库 |
推送保护 | 推送时向用户报告出现泄漏情况的对应令牌。 适用于启用机密推送保护的所有存储库。 |
有效期 | 高级安全尝试执行有效性检查的令牌。 |
合作伙伴提供程序模式
下表列出了密钥扫描支持的合作伙伴提供程序模式。
提供程序 | 令牌名称 | 推送保护 | 用户警报 | 有效性检查 |
---|---|---|---|---|
Adafruit IO | AdafruitIOKey | |||
Adobe | AdobeDeviceToken | |||
Adobe | AdobeServiceToken | |||
Adobe | AdobeShortLivedAccessToken | |||
Akamai | AkamaiCredentials | |||
Alibaba Cloud | AlibabaCloudCredentials | |||
Amazon | AmazonMwsAuthToken | |||
Amazon | AmazonOAuthCredentials | |||
Amazon | AwsCredentials | |||
Amazon | AwsTemporaryCredentials | |||
Asana | AsanaPat | |||
Atlassian | AtlassianApiToken | |||
Atlassian | AtlassianJwt | |||
Atlassian | BitbucketCloudOAuthCredentials | |||
Atlassian | BitbucketServerPat | |||
Beamer | BeamerApiKey | |||
Brevo | BrevoApiKey | |||
Brevo | BrevoSmtpKey | |||
Canadian Digital Service | CdsCanadaNotifyApiKey | |||
Checkout.com | CheckoutIdentifiableSecretKey | |||
Chief 工具 | ChiefToolsToken | |||
Cisco | CiscoLocalAccountCredentials | |||
Clojars | ClojarsDeployToken | |||
Cloudant | CloudantCredentials | |||
Cloudflare | CloudflareApiToken | |||
Contentful | ContentfulPersonalAccessToken | |||
Crates.io | CratesApiKey | |||
DevCycle | DevCycleClientApiKey | |||
DevCycle | DevCycleManagementApiToken | |||
DevCycle | DevCycleMobileApiKey | |||
DevCycle | DevCycleServerApiKey | |||
DigitalOcean | DigitalOceanOAuthToken | |||
DigitalOcean | DigitalOceanPat | |||
DigitalOcean | DigitalOceanRefreshToken | |||
DigitalOcean | DigitalOceanSystemToken | |||
Discord | DiscordApiCredentials | |||
Discord | DiscordApiToken | |||
Doppler | DopplerAuditToken | |||
Doppler | DopplerCliToken | |||
Doppler | DopplerPersonalToken | |||
Doppler | DopplerScimToken | |||
Doppler | DopplerServiceToken | |||
Dropbox | DropboxAccessToken | |||
Dropbox | DropboxAppCredentials | |||
Dropbox | DropboxOAuth2ShortLivedAccessToken | |||
Duffel | DuffelAccessToken | |||
Dynatrace | DynatraceInternalToken | |||
EasyPost | EasyPostApiKey | |||
Ebay | EBayProductionClientCredentials | |||
Ebay | EBaySandboxClientCredentials | |||
Elastic | ElasticCloudApiKey | |||
Elastic | ElasticStackApiKey | |||
EventBrite | PicaticApiKey | |||
FacebookAccessToken | ||||
FacebookAppCredentials | ||||
OculusAccessToken | ||||
Fastly | FastlyApiToken | |||
Figma | FigmaPat | |||
Finicity | FinicityAppKey | |||
Flutterwave | FlutterwaveLiveApiSecretKey | |||
Flutterwave | FlutterwaveTestApiSecretKey | |||
Frame.io | FrameIODeveloperToken | |||
Frame.io | FrameIOJwt | |||
FullStory | FullStoryApiKey | |||
GitHub | GitHubAppCredentials | |||
GitHub | GitHubAppToken | |||
GitHub | GitHubClassicPat | |||
GitHub | GitHubOAuthAccessToken | |||
GitHub | GitHubPat | |||
GitHub | GitHubRefreshToken | |||
GitHub | GitHubServerToServerToken | |||
GitHub | GitHubUserToServerToken | |||
GitLab | GitLabAccessToken | |||
GoCardless | GoCardlessLiveAccessToken | |||
GoCardless | GoCardlessSandboxAccessToken | |||
FirebaseCloudMessagingServerKey | ||||
GoogleApiKey | ||||
GoogleCloudPrivateKeyId | ||||
GoogleCloudStorageServiceAccountAccessKey | ||||
GoogleCloudStorageUserAccessKey | ||||
GoogleOAuthAccessToken | ||||
GoogleOAuthCredentials | ||||
GoogleOAuthRefreshToken | ||||
GoogleServiceAccountKey | ||||
Grafana | GrafanaApiKey | |||
Grafana | GrafanaCloudApiToken | |||
Grafana | GrafanaProjectApiKey | |||
Grafana | GrafanaProjectServiceAccountToken | |||
Hashicorp | HashiCorpVaultBatchLegacyToken | |||
Hashicorp | HashiCorpVaultBatchToken | |||
Hashicorp | HashiCorpVaultRootServiceToken | |||
Hashicorp | HashiCorpVaultServiceLegacyToken | |||
Hashicorp | HashiCorpVaultServiceToken | |||
Hashicorp | TerraformCloudEnterpriseToken | |||
HighNote | HighnoteRkKey | |||
HighNote | HighnoteSkKey | |||
HubSpot | HubspotApiKey | |||
HubSpot | HubSpotApiPersonalAccessKey | |||
HuggingFace | HuggingFaceAccessToken | |||
Intercom | IntercomAccessToken | |||
Ionic | IonicPat | |||
Ionic | IonicRefreshToken | |||
JD Cloud | JdCloudAccessKey | |||
JFrog | JFrogPlatformAccessToken | |||
JFrog | JFrogPlatformApiKey | |||
线性 | LinearApiKey | |||
线性 | LinearOAuthAccessToken | |||
Lob | LobLiveApiKey | |||
Lob | LobTestApiKey | |||
LocalStack | LocalStackApiKey | |||
LogicMonitor | LogicMonitorBearerToken | |||
LogicMonitor | LogicMonitorLmv1AccessKey | |||
MailChimp | MailChimpApiKey | |||
Mailgun | MailgunApiCredentials | |||
Mapbox | MapboxSecretAccessToken | |||
MessageBird | MessageBirdApiKey | |||
Microsoft | AadClientAppIdentifiableCredentials | |||
Microsoft | AdoPat | |||
Microsoft | AzureApimDirectManagementSas | |||
Microsoft | AzureApimGatewaySas | |||
Microsoft | AzureApimIdentifiableDirectManagementKey | |||
Microsoft | AzureApimIdentifiableGatewayKey | |||
Microsoft | AzureApimIdentifiableRepositoryKey | |||
Microsoft | AzureApimIdentifiableSubscriptionKey | |||
Microsoft | AzureApimLegacyDirectManagementKey | |||
Microsoft | AzureApimLegacyGatewayKey | |||
Microsoft | AzureApimLegacyRepositoryKey | |||
Microsoft | AzureApimLegacySubscriptionKey | |||
Microsoft | AzureApimRepositorySas | |||
Microsoft | AzureAppConfigurationCredentials | |||
Microsoft | AzureApplicationInsightsCredentials | |||
Microsoft | AzureBatchIdentifiableKey | |||
Microsoft | AzureBatchLegacyKey | |||
Microsoft | AzureBlockchainCredentials | |||
Microsoft | AzureCacheForRedisIdentifiableKey | |||
Microsoft | AzureCacheForRedisIdentifiablePrivateServiceKey | |||
Microsoft | AzureCacheForRedisLegacyKey | |||
Microsoft | AzureCdnSas | |||
Microsoft | AzureCognitiveServicesKey | |||
Microsoft | AzureCognitiveServicesTranslatorKey | |||
Microsoft | AzureCommunicationServicesKey | |||
Microsoft | AzureContainerRegistryIdentifiableKey | |||
Microsoft | AzureContainerRegistryLegacyKey | |||
Microsoft | AzureCosmosDBIdentifiableKey | |||
Microsoft | AzureCosmosDBIdentifiablePrivateServiceKey | |||
Microsoft | AzureCosmosDBLegacyKey | |||
Microsoft | AzureDatabricksPat | |||
Microsoft | AzureDevOpsOAuthToken | |||
Microsoft | AzureEventGridKey | |||
Microsoft | AzureEventHubIdentifiableKey | |||
Microsoft | AzureEventHubIdentifiablePrivateServiceSystemKey | |||
Microsoft | AzureFluidRelayKey | |||
Microsoft | AzureFunctionIdentifiableKey | |||
Microsoft | AzureFunctionLegacyKey | |||
Microsoft | AzureGenomicsKey | |||
Microsoft | AzureHDInsightCredentials | |||
Microsoft | AzureIotDeviceIdentifiableKey | |||
Microsoft | AzureIotDeviceLegacyCredentials | |||
Microsoft | AzureIotDeviceProvisioningIdentifiableKey | |||
Microsoft | AzureIotDeviceProvisioningLegacyCredentials | |||
Microsoft | AzureIotHubIdentifiableKey | |||
Microsoft | AzureIotHubLegacyCredentials | |||
Microsoft | AzureLogicAppSas | |||
Microsoft | AzureManagementCertificate | |||
Microsoft | AzureMapsKey | |||
Microsoft | AzureMixedRealityCredentials | |||
Microsoft | AzureMLIdentifiablePrivateServicePrincipalCredentials | |||
Microsoft | AzureMLWebServiceClassicIdentifiableKey | |||
Microsoft | AzureMLWebServiceKey | |||
Microsoft | AzureOpenAIKey | |||
Microsoft | AzureRelayIdentifiableKey | |||
Microsoft | AzureSearchIdentifiableAdminKey | |||
Microsoft | AzureSearchIdentifiablePrivateServiceAdminKey | |||
Microsoft | AzureSearchIdentifiableQueryKey | |||
Microsoft | AzureSearchLegacyKey | |||
Microsoft | AzureServiceBusIdentifiableKey | |||
Microsoft | AzureServiceBusIdentifiablePrivateServiceSystemKey | |||
Microsoft | AzureServiceBusLegacyCredentials | |||
Microsoft | AzureServiceDeploymentCredentials | |||
Microsoft | AzureSignalRKey | |||
Microsoft | AzureStorageAccountIdentifiableKey | |||
Microsoft | AzureStorageAccountLegacyCredentials | |||
Microsoft | AzureStorageIdentifiablePrivateServiceKey | |||
Microsoft | AzureStorageLooseSas | |||
Microsoft | AzureStorageSas | |||
Microsoft | AzureWebAppBotCredentials | |||
Microsoft | AzureWebAppBotKey | |||
Microsoft | AzureWebPubSubCredentials | |||
Microsoft | BingApiKey | |||
Microsoft | BingMapsKey | |||
Microsoft | BingSearchKey | |||
Microsoft | OfficeIncomingWebhook | |||
Microsoft | Sas | |||
Microsoft | SqlIdentifiableCredentials | |||
Microsoft | VisualStudioAppCenterKey | |||
Midtrans | MidtransServerKey | |||
New Relic | NewRelicInsightsQueryKey | |||
New Relic | NewRelicLicenseKey | |||
New Relic | NewRelicPersonalApiKey | |||
New Relic | NewRelicRestApiKey | |||
Notion | NotionIntegrationToken | |||
Notion | NotionOAuthClientCredentials | |||
npm | NpmAuthorIdentifiableToken | |||
npm | NpmCredentials | |||
npm | NpmLegacyAuthorToken | |||
NuGet | NuGetApiKey | |||
NuGet | NuGetCredentials | |||
Octopus 部署 | OctopusDeployApiKey | |||
Onfido | OnfidoApiToken | |||
OpenAI | OpenAIApiKeyV2 | |||
Palantir | PalantirJwt | |||
PayPal | PayPalBraintreeAccessToken | |||
角色 | PersonaProductionApiKey | |||
角色 | PersonaSandboxApiKey | |||
PineCone | PineconeApiKey | |||
PlanetScale | PlanetScaleDatabasePassword | |||
PlanetScale | PlanetScaleOAuthToken | |||
PlanetScale | PlanetScaleServiceToken | |||
Plivo | PlivoCredentials | |||
Prefect | PrefectServerApiToken | |||
Prefect | PrefectUserApiToken | |||
Proctorio | ProctorioConsumerKey | |||
Proctorio | ProctorioLinkageKey | |||
Proctorio | ProctorioRegistrationKey | |||
Proctorio | ProctorioSecretKeyV2 | |||
Pulumi | PulumiAccessToken | |||
PyPi | PyPiApiToken | |||
ReadMe | ReadMeApiKey | |||
redirect.pizza | RedirectPizzaApiToken | |||
Rubygems | RubyGemsApiKey | |||
SAMPLE | SecretScanningSampleToken | |||
Samsara | SamsaraApiAccessToken | |||
Samsara | SamsaraOAuth2AccessToken | |||
Segment.io | SegmentPublicApiToken | |||
SendGrid | SendGridApiKey | |||
Shippo | ShippoLiveApiToken | |||
Shippo | ShippoTestApiToken | |||
Shopify | ShopifyAccessToken | |||
Shopify | ShopifyAppClientCredentials | |||
Shopify | ShopifyAppClientSecret | |||
Shopify | ShopifyAppOAuthAccessToken | |||
Shopify | ShopifyCustomAppAccessToken | |||
Shopify | ShopifyMarketplaceToken | |||
Shopify | ShopifyMerchantToken | |||
Shopify | ShopifyPartnerApiToken | |||
Shopify | ShopifyPrivateAppPassword | |||
Shopify | ShopifySharedSecret | |||
Slack | SlackApiKey | |||
Slack | SlackAppLevelToken | |||
Slack | SlackWebhook | |||
Slack | SlackWorkflowKey | |||
Splunk | SplunkHecApiKey | |||
Splunk | SplunkJwtToken | |||
Splunk | SplunkSessionKey | |||
Square | SquareApplicationSecret | |||
Square | SquareCredentials | |||
Square | SquarePat | |||
SSLMate | SSLMateApiKey | |||
SSLMAte | SSLMateClusterSecret | |||
Stripe | StripeLiveApiKey | |||
Stripe | StripeLiveRestrictedApiKey | |||
Stripe | StripeTestApiKey | |||
Stripe | StripeTestRestrictedApiKey | |||
Stripe | StripeWebhookSigningSecret | |||
Supabase | SupabaseServiceKey | |||
画面 | TableauPersonalAccessToken | |||
Telegram | TelegramBotToken | |||
Telnyx | TelnyxApiV2Key | |||
Tencent Cloud | TencentCloudCredentials | |||
Tencent Cloud | TencentCloudSecretId | |||
Twilio | TwilioApiKeyCredentials | |||
Twilio | TwilioCredentials | |||
Typeform | TypeformPat | |||
Uniwise | WISEFlowApiKey | |||
WakaTime | WakaTimeAppCredentials | |||
WakaTime | WakaTimeOAuthAccessToken | |||
WakaTime | WakaTimeOAuthRefreshToken | |||
WorkOS | WorkOSProductionApiKey | |||
WorkOS | WorkOSStagingApiKey | |||
Yandex | YandexCloudApiKey | |||
Yandex | YandexCloudIamAccessSecret | |||
Yandex | YandexCloudIamCookie | |||
Yandex | YandexCloudIamToken | |||
Yandex | YandexDictionaryApiKey | |||
Yandex | YandexPassportOAuthToken | |||
Yandex | YandexPredictorApiKey | |||
Yandex | YandexTranslateApiKey | |||
Zuplo | ZuploConsumerApiKey |
非提供商模式
下表列出了通过密钥扫描检测到的非提供程序生成的密钥。 可通过从“密钥扫描”选项卡上的“置信度”下拉列表选择“其他”来查看非提供程序密钥。有关详细信息,请参阅管理密钥扫描警报。
提示
非提供程序模式的检测目前处于测试阶段,且可能会出现变化。
提供程序 | 支持的密钥 | 令牌名称 |
---|---|---|
常规 | ASP.NET 计算机密钥 | AspNetMachineKey |
常规 | DER 编码私钥 | DerPrivateKey |
常规 | Dynatrace 令牌 | DynatraceToken |
常规 | GPG 凭据 | GpgCredentials |
常规 | HTTP 请求头 | HttpAuthorizationRequestHeader |
常规 | JavaScript Web 令牌 | GenericJwt |
常规 | LinkedIn 凭据 | LinkedInCredentials |
常规 | MongoDB 连接字符串 | MongoDbCredentials |
常规 | MySQL/MariaDB 连接字符串 | MySqlCredentials |
常规 | 采用 PEM 编码的私钥 | PemPrivateKey |
常规 | PGP 私钥 | PgpPrivateKey |
常规 | 采用 PKCS12 格式的私钥 | Pkcs12PrivateKey |
常规 | PostgreSQL 连接字符串 | PostgreSqlCredentials |
常规 | Putty 私钥 | PuttyPrivateKey |
常规 | RabbitMQ 凭据 | RabbitMqCredentials |
常规 | RSA 私钥 | RsaPrivateKey |
常规 | SQL Server 连接字符串 | SqlLegacyCredentials |
常规 | SSH 私钥 | OpenSshPrivateKey |
常规 | SSH 私钥 | GitHubSshPrivateKey |
常规 | 采用 URL 编码的凭据 | UrlCredentials |