Git and GitHub

GitHub Security and Secrets

Learn to keep passwords, tokens and private data out of repositories and publish code without exposing credentials in this beginner-friendly Visual Studio Code lesson.

Learning outcomes

  • Explain how to keep passwords, tokens and private data out of repositories.
  • Complete the guided activity safely.
  • Check that you can publish code without exposing credentials.

Before you begin

Use a non-sensitive practice folder, inspect unfamiliar code before trusting it, and never place passwords, tokens or private information in project files.

Open official guidance ↗

Step-by-step instructions

  1. Open the intended practice workspace in Visual Studio Code and confirm its folder name and Workspace Trust state.
  2. Apply a pre-push secret checklist.
  3. Save the relevant files and review the Problems panel, terminal, Source Control view or browser preview as appropriate.
  4. Check filenames, relative paths, console messages, keyboard use, mobile layout and privacy before continuing.
  5. Confirm that you can publish code without exposing credentials, then create a clear commit, backup or saved checkpoint.
Ian's practical tip: Work in one named project folder, preview after small changes, read the actual error message and keep a recoverable version before broad edits.

Practical activity

Apply a pre-push secret checklist. The expected result is to publish code without exposing credentials.

Completion checklist