Repository rulesets allow you to easily add scalable protections across your repositories. Starting today, you can use repository rulesets to block pull requests from merging when the pull request introduces secret scanning alerts.

What’s new

You can enable the new rule require secret scanning alerts are resolved on pull requests for selected repositories. Developers without bypass permissions must clear the block by resolving each alert.

The rule checks two things before a pull request can merge:

A secret scan has completed for the head commit