Safeguard
Tag

credential-rotation

Safeguard articles tagged "credential-rotation" — guides, analysis, and best practices for software supply chain and application security.

13 articles

Cloud Security

One Shared Deploy Credential Is Forty Pipelines' Worth of Blast Radius

Set up once, when there was one service. Forty pipelines later, every one of them still uses it, and it can deploy to production, which means it can read the secrets and infrastructure of everything it touches.

Sep 18, 20266 min read
Application Security

Deleting the Line Does Not Delete the Secret From Git History

A scanner flags a credential from fourteen months ago, removed in the very next commit. The current file is clean, which feels like the problem is solved. The blob holding that value is still reachable from the earlier commit.

Sep 18, 20266 min read
Application Security

Design the API Key So It Can Be Found When It Leaks

A high-entropy string with no marker is invisible to every secret scanner, which makes yours the product that finds out last. A few decisions about the format buy a great deal.

Sep 18, 20265 min read
Incident Analysis

A Vendor Just Told You They Were Breached

The notification is vague, late, and does not say whether you are affected. It starts several clocks, and one of them may be a 72-hour regulatory deadline that runs from when you became aware, not when their investigation finishes.

Sep 18, 20266 min read
Incident Analysis

Your Dependency Incident Runbook Assumes a Fixed List of Bad Packages

Most supply chain runbooks say: get the affected package list, search lockfiles, remediate. Against a worm that adds packages while you work, every one of those steps is wrong.

Aug 9, 20267 min read
Supply Chain Attacks

The npm worm incident response playbook

Shai-Hulud compromised 500+ npm packages by auto-publishing itself with stolen tokens. Here's a concrete detection, rotation, and pinning playbook.

Jul 9, 20265 min read
DevSecOps

Credential rotation playbook after npm worm exposure

A step-by-step rotation runbook for security teams exposed to the Shai-Hulud npm worm — what to revoke first, how to verify a credential is dead, and how to prevent a repeat.

Jul 9, 20266 min read
Best Practices

The complete workflow for finding and remediating hardcoded secrets in GitHub

GitGuardian found 12.8 million secrets leaked on public GitHub in 2023 alone, and over 90% were still valid five days later. Here's the fix workflow that actually closes the gap.

Jul 8, 20268 min read
Supply Chain Attacks

Anatomy of a self-propagating npm worm

In September 2025, one phished maintainer account led to malicious chalk and debug releases hitting over 2B weekly downloads within two hours.

Jul 8, 20267 min read
Security Guides

How to Rotate Leaked API Keys (2026 Playbook)

A leaked API key is a live credential until you kill it. Here is a provider-agnostic rotation playbook — grounded in the Toyota T-Connect and CircleCI incidents — that revokes access without breaking production.

Jul 1, 20267 min read
Cloud Security

Cloudflare R2 March 21, 2025 Outage: A Credential Rotation Postmortem

A missing --env flag during a Wrangler secret rotation took R2 writes to zero for 67 minutes. Here is the failure mode and the deployment guardrails that should have caught it.

Apr 11, 20267 min read
Guides

How to Rotate Leaked CI Secrets Without Downtime

A leaked CI credential does not have to mean an outage. The dual-credential pattern: issue new alongside old, cut over, verify with usage logs, then revoke — plus what to do after.

Mar 13, 20266 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.