Safeguard
Tag

secrets

Safeguard articles tagged "secrets" — guides, analysis, and best practices for software supply chain and application security.

41 articles

Cloud Security

One Shared Deploy Credential Is Forty Pipelines' Worth of Blast Radius

Set up once, when there was one service. Forty pipelines later, every one of them still uses it, and it can deploy to production, which means it can read the secrets and infrastructure of everything it touches.

Sep 18, 20266 min read
DevSecOps

CI Secret Masking Matches the Exact String, and Almost Nothing Else

Encode it, uppercase it, split it across two log lines, and masking has nothing to match against. This is not a bug in any platform. It is the only mechanism possible without semantic analysis of every command a pipeline runs.

Sep 18, 20266 min read
Application Security

Search Your Wiki for the Word Password Right Now

A database credential pasted into a setup guide, an API key in a runbook written during an outage, a shared vendor login on a page titled useful links. Nobody put it there to be careless, and it has been searchable ever since.

Sep 18, 20266 min read
Application Security

Deleting the Line Does Not Delete the Secret From Git History

A scanner flags a credential from fourteen months ago, removed in the very next commit. The current file is clean, which feels like the problem is solved. The blob holding that value is still reachable from the earlier commit.

Sep 18, 20266 min read
Cloud Security

Your Terraform State Is a Secrets Store With a Build Artefact's Access Control

The database password, the generated private key, the API token an output exposed. You did not put them there directly. Terraform did, because it needs the full attributes of everything it manages to plan the next change.

Sep 18, 20265 min read
Infrastructure Security

Your Staging Environment Is on the Internet and Nobody Chose That

Less hardening, unfinished code, no monitoring, real credentials, and often production's network reachability. An attacker choosing between your two environments will frequently prefer this one.

Sep 18, 20265 min read
Application Security

Design the API Key So It Can Be Found When It Leaks

A high-entropy string with no marker is invisible to every secret scanner, which makes yours the product that finds out last. A few decisions about the format buy a great deal.

Sep 18, 20265 min read
Application Security

Your Config Parser Is an Interpreter and the File Chooses What It Does

Configuration feels inert because it looks like data. Several formats can execute code and several loaders will by default, which makes parsing a security decision the moment the file comes from anywhere but your own repository.

Sep 18, 20265 min read
Application Security

The Notebook Nobody Reviewed Is Running on a Schedule

It pulls customer records, holds a password in cell four, installs packages at runtime, and has run nightly for eighteen months. The format hides both the state and the data, and nothing gated the moment it became infrastructure.

Sep 17, 20266 min read
Application Security

Your Logs Are the Least Protected Copy of Your Most Sensitive Data

Nobody writes log.info(password). The leaks come from logging whole request bodies, exception objects, header maps and serialised domain objects, into a store replicated everywhere and retained for a year.

Sep 17, 20266 min read
Open Source Security

Seventeen Fake Payment SDKs, Six Minutes to Detection, and a Sandbox Check

On 7 July 2026, roughly 17 typosquatted payment-provider packages hit npm and PyPI — paysafe-checkout, paysafe-node, neteller and friends. They swept environment variables matching KEY, SECRET, TOKEN, PASS, AUTH and API, explicitly hunted AWS_SECRET_ACCESS_KEY, GITHUB_TOKEN and NPM_TOKEN, and exited quietly if they thought they were in a sandbox.

Jul 28, 20266 min read
Security Guides

OIDC vs Static Credentials in CI/CD (2026 Guide)

Static secrets in CI are the credential most likely to be stolen — as the CircleCI breach proved. OIDC federation issues short-lived, per-run credentials with nothing to leak. Here is how to make the switch.

Jul 8, 20266 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.