Block pull requests with exposed secrets from merging
Repository rulesets allow you to easily add scalable protections across your repositories. Starting today, you can use repository rulesets to block pull requests from merging when the pull request introduces secret scanning alerts. What’s new You can enable the new rule require secret scanning alerts are resolved on pull requests for selected repositories.
Read GitHub's release noteshttps://github.blog/changelog/2026-09-09-block-pull-requests-with-exposed-secrets-from-merging
Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.
More GitHub Advanced Security releases
npm extends recovery-code security holds to all accounts
UpdateSecurityObservability
GitHub Advanced Security expands trial availability
UpdateSecurityPricingObservability
Remediate Code Quality findings with agentic autofix
UpdateAI agentsGovernancePricing
AI Scan for pull request APIs in public preview
PreviewSecurityObservabilityDeveloper tools
Automatic Dependabot access to GitHub-hosted registries
UpdateDeveloper tools
Enforce GitHub Advanced Security configurations
UpdateGovernanceSecurityObservability