Skip to content

COMMUNITY

Tell us what broke
or what's missing

Pick what you want to tell us. You fill a short form here, this page checks it for secrets in your browser, and GitHub opens with the form already filled in. You review it and press Submit there.

  • Nothing is sent from this page. The check runs in your browser.
  • Reports are public. They land in redact-secret/redact-secret.
  • Best-effort support. No response-time promise.

This page needs JavaScript to check your report. Without it, choose a blank form on GitHub and never paste a real credential.

Bug report

Issue formbug-report.ymllabelsbugSource

For code defects. If a value was flagged when it shouldn't be, or missed when it should be caught, use False positive or Missed detection instead.

Required

One line. GitHub adds the prefix.

Required
Required
Required
Required

Only independently authored synthetic values. Never a real credential, even truncated or masked.

Safety acknowledgementRequired

Check and continue

Not checked yet
The check runs as you type once a field has text.
GitHub address this opens98 of 8,000 characters
https://github.com/redact-secret/redact-secret/issues/new?template=bug-report.yml&title=%5Bbug%5D+

Continue is off until:

  • required fields are filled: Short title, Package and exact version, Binding and runtime, What happened, and what did you expect instead?, Minimal synthetic reproduction
  • the safety checkbox is ticked

What you typed goes into the GitHub address, so it also stays in your browser history. GitHub asks you to confirm the safety checkbox again before you submit.

The check on this page is preventive. It cannot see what you type on GitHub, and it is not the product's enforcement boundary.