Skip to content

Block pull requests with exposed secrets from merging

PreviewVerifiedAdded Sep 22, 2026

Repository rulesets allow you to easily add scalable protections across your repositories. Starting today, you can use repository rulesets to block pull requests from merging when the pull request introduces secret scanning alerts. What’s new You can enable the new rule require secret scanning alerts are resolved on pull requests for selected repositories.

Read GitHub's release notes

https://github.blog/changelog/2026-09-09-block-pull-requests-with-exposed-secrets-from-merging

Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.

More GitHub Advanced Security releases

npm extends recovery-code security holds to all accounts

Update

CodeQL 2.27.0 adds support for Linux ARM64

Update

Remediate Code Quality findings with agentic autofix

Update

AI Scan for pull request APIs in public preview

Preview

Enforce GitHub Advanced Security configurations

Update

Multiple trusted publishing configurations for npm

Also shipped on Sep 9, 2026

External secrets in Unity Catalog (Beta)

Beta
DatabricksLakeflow

Celigo connector (Beta)

Beta
DatabricksLakeflow

Anysphere Organization connector (Beta)

Beta
DatabricksLakeflow

Anaplan connector (Beta)

Beta

Openflow gen 1 deployment creation retired

Deprecation

Weekly: the week's data and AI releases, Tuesday mornings.