I wish I could set this up to block pushes proactively instead of reacting to pushed secrets.
https://docs.github.com/en/enterprise-cloud@latest/code-secu...
It can be as simple as a script you have to run once, but it can't be automatic. Which also means you can't really trust contributors to do it, even if they're well-meaning some will forget.