Secret protection has to scale with the software

Developers are not becoming more careless; they are being outpaced. Tools that help ship more code should take on more of the work of protecting it.
Every year the number of credentials committed by accident goes up. Every year the share of developers who do it stays roughly flat. The difference is volume.
Push protection by default
Blocking a secret before it lands is cheaper than rotating one afterwards. This quarter push protection is on by default for every new repository.
// .forgeline/secret-scanning.js
export default {
pushProtection: "enforce",
customPatterns: [{ name: "internal-token", regex: "itk_[A-Za-z0-9]{32}" }],
};What changes for you
Nothing, until it matters. When it does, you will see the block in your terminal with a link to rotate the credential.