GitHub expanded secret scanning on October 5, 2026. Five credential and access-token types issued by Lovable Labs, Pydantic Services, and Supabase are now recognized as supported secret patterns in repositories. The change lets GitHub identify these values as known credential types rather than treating them as ordinary strings. Source

The update adds five specific patterns

The new patterns are Lovable’s lovable_api_key; Pydantic’s logfire_token and pydantic_ai_gateway_api_key; and Supabase’s supabase_oauth_access_token and supabase_scoped_personal_access_token. GitHub says secret scanning now detects all five automatically in repositories. Source

The provider name alone is not enough to decide whether a credential is covered by this update. For Supabase, the announcement names the OAuth access token and scoped personal access token. For Pydantic, it names the Logfire token and AI Gateway API key. Review the secret type shown in an alert instead of assuming that every key from the same provider was newly added. Source

Public Lovable leaks can be reported to the issuer

Lovable Labs also joined GitHub’s secret scanning partnership program. When a partner secret is found in a public repository, GitHub forwards it to the issuer so the credential can be revoked or rotated before abuse. The newly listed Lovable partner secret is lovable_api_key. Source

GitHub distinguishes that partner flow from user-secret alerts. Partner secrets found in public repositories are automatically reported to the issuer. User secrets generate secret scanning alerts when found in public or private repositories. The announcement does not say that a credential found in a private repository is automatically sent to an external issuer. Source

Start with credential rotation when an alert is real

First confirm the secret type and the file and commit location shown by the alert. If the value is an active credential, revoke or rotate it with the provider, then update the deployment environment and application configuration that consume it. Removing the string from the repository does not by itself invalidate a credential that has already been exposed.

If an alert appears to be a false positive, record the provider, token type, and repository visibility so later reports can be reviewed consistently. This changelog announces support for the new patterns but does not state account- or plan-specific availability. Check whether secret scanning is enabled and who can view alerts in the relevant repository or organization settings. Source

What changes for development teams

Tokens for fast-moving services such as Lovable, Pydantic AI Gateway, and Supabase can be committed accidentally through local configuration or example code. GitHub can now recognize these five supported formats directly. Detection still does not guarantee coverage of every credential or altered string, so environment-variable discipline, least privilege, and regular rotation remain necessary controls.