IssueGuard: Real-Time Secret Leak Prevention Tool for GitHub Issue Reports

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Rahman, Md Nafiu, Ahmed, Sadif, Wahab, Zahin, Uddin, Gias, Shahriyar, Rifat
Formato: Preprint
Publicado: 2026
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866908947062980608
author Rahman, Md Nafiu
Ahmed, Sadif
Wahab, Zahin
Uddin, Gias
Shahriyar, Rifat
author_facet Rahman, Md Nafiu
Ahmed, Sadif
Wahab, Zahin
Uddin, Gias
Shahriyar, Rifat
contents GitHub and GitLab are widely used collaborative platforms whose issue-tracking systems contain large volumes of unstructured text, including logs, code snippets, and configuration examples. This creates a significant risk of accidental secret exposure, such as API keys and credentials, yet these platforms provide no mechanism to warn users before submission. We present \textsc{IssueGuard}, a tool for real-time detection and prevention of secret leaks in issue reports. Implemented as a Chrome extension, \textsc{IssueGuard} analyzes text as users type and combines regex-based candidate extraction with a fine-tuned CodeBERT model for contextual classification. This approach effectively separates real secrets from false positives and achieves an F1-score of 92.70\% on a benchmark dataset, outperforming traditional regex-based scanners. \textsc{IssueGuard} integrates directly into the web interface and continuously analyzes the issue editor, presenting clear visual warnings to help users avoid submitting sensitive data. The source code is publicly available at \href{https://github.com/disa-lab/IssueGuard}{https://github.com/disa-lab/IssueGuard} , and a demonstration video is available at \href{https://youtu.be/kvbWA8rr9cU}{https://youtu.be/kvbWA8rr9cU} .
format Preprint
id arxiv_https___arxiv_org_abs_2602_08072
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle IssueGuard: Real-Time Secret Leak Prevention Tool for GitHub Issue Reports
Rahman, Md Nafiu
Ahmed, Sadif
Wahab, Zahin
Uddin, Gias
Shahriyar, Rifat
Cryptography and Security
Software Engineering
GitHub and GitLab are widely used collaborative platforms whose issue-tracking systems contain large volumes of unstructured text, including logs, code snippets, and configuration examples. This creates a significant risk of accidental secret exposure, such as API keys and credentials, yet these platforms provide no mechanism to warn users before submission. We present \textsc{IssueGuard}, a tool for real-time detection and prevention of secret leaks in issue reports. Implemented as a Chrome extension, \textsc{IssueGuard} analyzes text as users type and combines regex-based candidate extraction with a fine-tuned CodeBERT model for contextual classification. This approach effectively separates real secrets from false positives and achieves an F1-score of 92.70\% on a benchmark dataset, outperforming traditional regex-based scanners. \textsc{IssueGuard} integrates directly into the web interface and continuously analyzes the issue editor, presenting clear visual warnings to help users avoid submitting sensitive data. The source code is publicly available at \href{https://github.com/disa-lab/IssueGuard}{https://github.com/disa-lab/IssueGuard} , and a demonstration video is available at \href{https://youtu.be/kvbWA8rr9cU}{https://youtu.be/kvbWA8rr9cU} .
title IssueGuard: Real-Time Secret Leak Prevention Tool for GitHub Issue Reports
topic Cryptography and Security
Software Engineering
url https://arxiv.org/abs/2602.08072