Secret scanning adds detectors for Lovable, Supabase, and more
By Steven Van ·
Lovable joins the partner program, allowing GitHub to report exposed API keys in public repositories directly to the provider.
Five newly supported credential types expand GitHub secret scanning’s coverage across Lovable Labs, Pydantic Services Inc., and Supabase. Lovable Labs has also joined the secret scanning partnership program.
New credential detectors
- Lovable Labs: lovable_api_key.
- Pydantic Services Inc.: logfire_token and pydantic_ai_gateway_api_key.
- Supabase: supabase_oauth_access_token and supabase_scoped_personal_access_token.
Secret scanning checks the entire Git history across all repository branches. GitHub also periodically rescans repositories when new secret types are added.
Partner reporting and repository alerts
When a Lovable API key is found in a public repository, GitHub forwards it to Lovable Labs so the provider can revoke or rotate it. Partner secrets are reported directly to their issuer and do not appear in repository alerts. User secrets generate secret scanning alerts when found in public or private repositories.
Availability
Secret scanning runs automatically for free in public repositories. Organization-owned private and internal repositories require GitHub Secret Protection on GitHub Team or GitHub Enterprise Cloud. User-owned repositories are supported on GitHub Enterprise Cloud with Enterprise Managed Users, and on GitHub Enterprise Server when the enterprise has GitHub Secret Protection enabled.
GitHub’s secret scanning documentation explains detection, alerts, and partner reporting.
