Deactivate pushing of secrets to bypass through own approval #182111
Replies: 1 comment
-
|
You can disable the direct self-approval link (The "Allow This Secret" URL) and force a review process instead by enabling Delegated bypass for push protection. This feature (Available In GitHub Advanced Security / Secret Protection, Typically On Team+ Plans With The Right Licensing) lets organization/repo admins create a list of users/teams/roles who can bypass directly. Everyone else must submit a bypass request that only designated reviewers (Admins/Security Managers) can approve/deny. How to set it up? Once enabled, regular users see no direct bypass link — they must request approval → only admins/reviewers decide. |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Select Topic Area
Question
Body
Hi
I have set up Secrets Push Protection. However, I do not want the user to be able to push the secret via the link "To push, remove secret from commit(s) or follow this URL to allow the secret." and their own approval.
How can I deactivate or restrict this so that only an administrator can approve it?
To push, remove secret from commit(s) or follow this URL to allow the secret.
Beta Was this translation helpful? Give feedback.
All reactions