GitHub Advanced Security for Azure DevOps just got sharper: it now checks if leaked secrets are actually valid. Secrets are flagged as Active or Unknown by pinging providers in real time.
No setup needed. It auto-kicks in for supported secret types.
Why care? Because not every secret leak is an emergency. Validity checks cut the noise and push the real risks to the top, so teams can triage faster and smarter.