Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's not necessary to perform secret scanning on a per-commit basis. The most efficient way is to just scan all blob objects being pushed; there is no reason to even be aware of an object's location (tree path or commit) except for diagnostic messages.

> I can navigate in GitHub directly to any individual commit

You can do the same with the git command line client. The overhead you claim is already in the git on-disk format. Github might very well duplicate this information in a database somewhere, but it doesn't follow from your observation.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: