Secrets in code
TL;DR
Hardcoded secrets — passwords, API keys, tokens — are one of the easiest and most common findings in a codebase. They leak through source, config and, notoriously, git history. Find them, get them out, and rotate them.
What it is
A secret written into the code or config is a credential sitting in plain sight for anyone who can read the repo. And “delete it later” doesn’t work — it stays in the git history unless you rewrite it.
How to find them
- Grep for the obvious words:
password,secret,api_key,token,BEGIN PRIVATE KEY. - Check config files, environment files committed by mistake, and comments.
- Search the git history, not just the current files — secret scanners exist precisely for this.
How to fix it
- Rotate anything that was exposed — assume it’s burned.
- Move secrets to environment variables or a secrets manager, and keep them out of the repo.
- Purge them from git history, and add scanning to CI so it doesn’t happen again.