Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Validity-Override API Tutorial: Confirm If a Leaked Secret Is Still Exploitable

GitGuardian's validity-override API lets security and engineering teams tell GitGuardian whether an exposed credential is actually valid, even when automatic checks mark it as Failed to Check. Secrets tied to internal services, private APIs, or systems GitGuardian cannot reach often fall into this category. GitGuardian automatically validates most supported credential types, but when it cannot, teams can now perform their own validation and feed the result back into the platform.

Introducing GitGuardian Developer Endpoint Protection: Inventory Every Laptop's Credentials

A single compromised laptop can mean weeks of manual credential hunting, or hours of clear, prioritized action. See how GitGuardian Developer Endpoint Protection inventories every credential on a developer's machine so your security team can map the blast radius fast. When an attacker compromises a developer laptop, traditional endpoint tools cannot tell you what credentials were exposed.

Developer Endpoint Protection: Stop Secrets Leaking From Laptops | GitGuardian

Every developer laptop is a credential store: secrets hide in.env files, config files, and shell history, and every AI agent on the machine keeps adding more. Most teams already scan repositories and CI pipelines for secrets, but a secret lands on the laptop long before it reaches either one, and that's the place nobody scans. GitGuardian's Developer Endpoint Protection closes that gap.

It Just Got Easier To Consistently Deploy And Configure ggshield Across Your Whole Fleet With v1.53

ggshield v1.53.0 introduces ggshield machine setup, a consistent way to configure ggshield no matter how it was installed. Set up AI hooks for every detected AI coding assistant, install global git pre-commit/pre-push hooks, and deploy a honeytoken on the endpoint. You have full control, and we have options to customize which features you want to skip. This release also includes ggshield machine doctor, a read-only command that checks that the machine's ggshield protections are correctly set up, letting you know what steps to take if it encounters an issue.

Every laptop is a credential store: lessons from Vermeer

Your code repos aren't the only place secrets hide — your laptop is too. In this session, GitGuardian's Emanuelle Franquelin talks with CJ May, Cybersecurity Architect at Vermeer, about extending secrets detection beyond the codebase and onto developer endpoints. They dig into where credentials actually live on modern machines (think config files, shell history, and AI coding agents), why every workstation is fair game, and what to actually do once you find exposed secrets. Watch to see how one enterprise team is tackling credential sprawl to deploy AI safely.

GitGuardian Smart Notifiers: Filter Incident Alerts by Risk, Severity, and More

Every secret leak matters, but not every incident needs the same level of alerting. GitGuardian’s new Smart Notifiers let teams define per-channel rules so notifications are only sent for the incidents that matter most, using filters like severity, ML risk score, validity, secret type, and GitGuardian tags. This is available now for custom webhooks, Slack, and Microsoft Teams. We will be adding support for ServiceNow, Jira, Splunk, PagerDuty, Discord, and broader email filtering coming next.