A study conducted by Truffle Security found that 543,699 unique credentials were still valid and exposed in public GitHub repositories during July, despite the platform’s tools designed to prevent the accidental publication of sensitive secrets. The findings followed an analysis of data covering 224 million repositories and more than 58 billion files, including copies of forked repositories.
The problem was not limited to recent secrets; unique credentials remained publicly accessible for a median period of 784 days. About 10% of the active credentials were more than 6.3 years old, while the oldest valid credential detected by the study dated back to 2009.
Scope and Direction of the Exposure
The credentials counted in the study appeared in more than 1.1 million files and repositories. The analysis was based on a dataset prepared to train large language models, using a crawl completed on August 7, 2025.
Truffle Security says the number is more than double what it detected in August when examining the Hugging Face platform, where it found 221,303 active credentials. The density of active secrets also increased from 3.72 per million files in 2015 to a peak of 11.62 in 2025.
What Did Push Protection Change?
GitHub introduced the Push Protection feature in April 2022 for Advanced Security users, then made it available to public repositories in May 2023, before enabling it by default a year later. The feature scans incoming code for known patterns, such as API keys and access tokens, and blocks the upload when it detects them.
However, the feature does not revoke or disable credentials that were exposed before they were detected. Among the credentials that were still active in July, 199,843 had been exposed after Push Protection was enabled for all users in February 2024, representing about 36.8% of the total. In addition, 51.8% of the active credentials belonged to categories not blocked by the default protection, including database connection strings and Google API keys.
Nevertheless, the feature appeared effective within its coverage scope: the rate of credential exposure in protected categories fell by 53% after it was enabled by default.
Why Does This News Matter?
The findings show that preventing a new secret from being uploaded does not address the entire risk. Secrets may remain in a repository’s history or its forked copies for long periods, and the effectiveness of the response varies depending on the type of credential and the associated service.
For example, only one npm token out of 101,886 exposed tokens remained valid, while 69,041 out of 126,963 credentials for Google Cloud service accounts were still valid at the time of the analysis. Truffle Security recommends immediately rotating exposed credentials, cleaning repositories, examining the change history, and setting automatic expiration for active secrets.
The study does not determine the percentage of secrets that were actually stolen or used in attacks, so it measures the volume of exploitable exposure, not the extent of confirmed damage. This remains one of the open questions that should not be conflated with the number of valid credentials detected.