credential-rotation
Safeguard articles tagged "credential-rotation" — guides, analysis, and best practices for software supply chain and application security.
13 articles
One Shared Deploy Credential Is Forty Pipelines' Worth of Blast Radius
Set up once, when there was one service. Forty pipelines later, every one of them still uses it, and it can deploy to production, which means it can read the secrets and infrastructure of everything it touches.
Deleting the Line Does Not Delete the Secret From Git History
A scanner flags a credential from fourteen months ago, removed in the very next commit. The current file is clean, which feels like the problem is solved. The blob holding that value is still reachable from the earlier commit.
Design the API Key So It Can Be Found When It Leaks
A high-entropy string with no marker is invisible to every secret scanner, which makes yours the product that finds out last. A few decisions about the format buy a great deal.
A Vendor Just Told You They Were Breached
The notification is vague, late, and does not say whether you are affected. It starts several clocks, and one of them may be a 72-hour regulatory deadline that runs from when you became aware, not when their investigation finishes.
Your Dependency Incident Runbook Assumes a Fixed List of Bad Packages
Most supply chain runbooks say: get the affected package list, search lockfiles, remediate. Against a worm that adds packages while you work, every one of those steps is wrong.
The npm worm incident response playbook
Shai-Hulud compromised 500+ npm packages by auto-publishing itself with stolen tokens. Here's a concrete detection, rotation, and pinning playbook.
Credential rotation playbook after npm worm exposure
A step-by-step rotation runbook for security teams exposed to the Shai-Hulud npm worm — what to revoke first, how to verify a credential is dead, and how to prevent a repeat.
The complete workflow for finding and remediating hardcoded secrets in GitHub
GitGuardian found 12.8 million secrets leaked on public GitHub in 2023 alone, and over 90% were still valid five days later. Here's the fix workflow that actually closes the gap.
Anatomy of a self-propagating npm worm
In September 2025, one phished maintainer account led to malicious chalk and debug releases hitting over 2B weekly downloads within two hours.
How to Rotate Leaked API Keys (2026 Playbook)
A leaked API key is a live credential until you kill it. Here is a provider-agnostic rotation playbook — grounded in the Toyota T-Connect and CircleCI incidents — that revokes access without breaking production.
Cloudflare R2 March 21, 2025 Outage: A Credential Rotation Postmortem
A missing --env flag during a Wrangler secret rotation took R2 writes to zero for 67 minutes. Here is the failure mode and the deployment guardrails that should have caught it.
How to Rotate Leaked CI Secrets Without Downtime
A leaked CI credential does not have to mean an outage. The dual-credential pattern: issue new alongside old, cut over, verify with usage logs, then revoke — plus what to do after.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.