GitHub discovered over 20,000 secret scanning alerts spread across 15,000+ repositories. Through a phased approach of enabling protections, triaging alerts, validating active credentials, establishing ownership, and systematizing workflows, the organization reached zero open alerts in nine months, largely by automating what it previously handled manually.