secrets
Safeguard articles tagged "secrets" — guides, analysis, and best practices for software supply chain and application security.
41 articles
One Shared Deploy Credential Is Forty Pipelines' Worth of Blast Radius
Set up once, when there was one service. Forty pipelines later, every one of them still uses it, and it can deploy to production, which means it can read the secrets and infrastructure of everything it touches.
CI Secret Masking Matches the Exact String, and Almost Nothing Else
Encode it, uppercase it, split it across two log lines, and masking has nothing to match against. This is not a bug in any platform. It is the only mechanism possible without semantic analysis of every command a pipeline runs.
Search Your Wiki for the Word Password Right Now
A database credential pasted into a setup guide, an API key in a runbook written during an outage, a shared vendor login on a page titled useful links. Nobody put it there to be careless, and it has been searchable ever since.
Deleting the Line Does Not Delete the Secret From Git History
A scanner flags a credential from fourteen months ago, removed in the very next commit. The current file is clean, which feels like the problem is solved. The blob holding that value is still reachable from the earlier commit.
Your Terraform State Is a Secrets Store With a Build Artefact's Access Control
The database password, the generated private key, the API token an output exposed. You did not put them there directly. Terraform did, because it needs the full attributes of everything it manages to plan the next change.
Your Staging Environment Is on the Internet and Nobody Chose That
Less hardening, unfinished code, no monitoring, real credentials, and often production's network reachability. An attacker choosing between your two environments will frequently prefer this one.
Design the API Key So It Can Be Found When It Leaks
A high-entropy string with no marker is invisible to every secret scanner, which makes yours the product that finds out last. A few decisions about the format buy a great deal.
Your Config Parser Is an Interpreter and the File Chooses What It Does
Configuration feels inert because it looks like data. Several formats can execute code and several loaders will by default, which makes parsing a security decision the moment the file comes from anywhere but your own repository.
The Notebook Nobody Reviewed Is Running on a Schedule
It pulls customer records, holds a password in cell four, installs packages at runtime, and has run nightly for eighteen months. The format hides both the state and the data, and nothing gated the moment it became infrastructure.
Your Logs Are the Least Protected Copy of Your Most Sensitive Data
Nobody writes log.info(password). The leaks come from logging whole request bodies, exception objects, header maps and serialised domain objects, into a store replicated everywhere and retained for a year.
Seventeen Fake Payment SDKs, Six Minutes to Detection, and a Sandbox Check
On 7 July 2026, roughly 17 typosquatted payment-provider packages hit npm and PyPI — paysafe-checkout, paysafe-node, neteller and friends. They swept environment variables matching KEY, SECRET, TOKEN, PASS, AUTH and API, explicitly hunted AWS_SECRET_ACCESS_KEY, GITHUB_TOKEN and NPM_TOKEN, and exited quietly if they thought they were in a sandbox.
OIDC vs Static Credentials in CI/CD (2026 Guide)
Static secrets in CI are the credential most likely to be stolen — as the CircleCI breach proved. OIDC federation issues short-lived, per-run credentials with nothing to leak. Here is how to make the switch.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.