Secrets scanning detects credentials that leak into places they should not be: API keys, database passwords, cloud tokens, and certificates committed to repositories, embedded in pipeline definitions, or pasted into configuration. A leaked secret is an incident, not a finding — it must be revoked, not just fixed forward.

How detection works

Scanners combine high-precision patterns for known credential formats (cloud keys have recognizable shapes), entropy analysis for random-looking strings, and validity checking — testing whether a candidate credential actually authenticates — to separate live leaks from noise.

Where to catch secrets

  • Pre-commit and PR: the cheapest catch — the secret never lands in history.
  • Repository history: secrets committed long ago remain live until rotated.
  • Pipeline surfaces: variable groups, service connections, and logs leak too — not just code.

Why the estate view matters

A secrets program that scans some repositories is a false comfort: attackers enumerate everything. Coverage — every repo, every new pipeline, by default — is the property that makes secrets scanning meaningful.

RELATED CONCEPTS