# The Python Package Index is now a GitHub secret scanning integrator

DevFeed: [The Python Package Index is now a GitHub secret scanning integrator](<https://devfeed.tech/articles/the-python-package-index-is-now-a-github-secret-scanning-integrator-74507.md>)

Original publisher: [Read original article](<https://github.blog/changelog/2021-03-22-the-python-package-index-is-now-a-github-secret-scanning-integrator>)

Author: phanatic

Published: 2021-03-22T20:33:02Z

Content type: release

Language: en

Sources: [GitHub Changelog](<https://devfeed.tech/sources/github-changelog.md>)

Topics: [Secret Scanning](<https://devfeed.tech/topics/secret-scanning.md>), [PyPI](<https://devfeed.tech/topics/pypi.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [github](<https://devfeed.tech/tags/github.md>), [github-advanced-security](<https://devfeed.tech/tags/github-advanced-security.md>), [pypi](<https://devfeed.tech/tags/pypi.md>), [python](<https://devfeed.tech/tags/python.md>), [scanning](<https://devfeed.tech/tags/scanning.md>), [secret](<https://devfeed.tech/tags/secret.md>), [tokens](<https://devfeed.tech/tags/tokens.md>)

## AI overview

GitHub and PyPI began collaborating to protect against leaked PyPI API tokens. GitHub scans commits to public repositories, forwards exposed tokens to PyPI for automatic disabling, and notifies token owners. GitHub Advanced Security customers can also scan private repositories for leaked secrets.

## Source excerpt

GitHub and the Python Package Index (PyPI) are collaborating to help protect you from leaked PyPI API tokens. From today, GitHub will scan every commit to a public repository for...