October 1, 2026
Enable GitHub leak protection with a command: gh-secure configures your repository
gh-secure enables protection against pushing secrets and 4 more features for a public repository for free.

GitHub
@github
Just one command can help you stop pushing secrets to public code. Set up basic protection for your repositories with gh-secure from GitHub Security Lab. ✅ Install it and use it in the Copilot app, Copilot CLI or GitHub CLI. https://gh.io/gh-secure
· 6.8K views
GitHub Security Lab says gh-secure can configure 5 security features in no more than 2 minutes, according to information available on Oct 1.
In a July guide, GitHub engineer Joseph Katsioloudes recommended enabling 6 free settings through the step-by-step Protect Your Project guide in under 30 minutes. Now gh-secure brings that setup into a GitHub CLI command. The listed features are free for public open source repositories.
What gets enabled. The extension configures branch protection and code checks, along with secret and vulnerability detection:
- Branch Protection protects branches. - Private Vulnerability Reporting lets people report vulnerabilities privately. - Secret Scanning detects secrets. - Dependabot checks dependencies. - Code Scanning checks code using CodeQL.
Secret Scanning with push protection recognizes over 300 token types and patterns from more than 180 providers, according to GitHub Security Lab as of Oct 1. Push protection blocks pushes containing detected secrets, while Secret Scanning creates alerts for secrets in repository history.
How to set it up. You need GitHub CLI installed and admin or maintain permissions on the repository. Authentication and installation take two commands:
```sh gh auth login gh extension install GitHubSecurityLab/gh-secure ```
The `gh secure` command starts an interactive setup. `gh secure --yes` enables all features without further prompts. To enable selected features, pass their names: `gh secure branch-protection dependabot` enables only branch protection and Dependabot.
The `gh secure --yes --dry-run` command shows the plan without making changes. `gh secure status --repo owner/repo` checks the settings of the specified repository.
In the GitHub Copilot app and GitHub Copilot CLI, you can ask for a repository security review and have missing features enabled through the installed gh-secure extension.
Repository settings can be enabled through Copilot or directly through GitHub CLI.
Source

