GitHub PM here, just confirming that that's correct (re: us sending detected secrets to the relevant service provider, who take action automatically). There's more detail here: https://docs.github.com/en/code-security/secret-scanning/abo....
Thanks for keeping an eye out.