Hardcoded secrets

Overview

A recurring problem when developing applications is that people may accidentally hardcode and commit secrets to their remote Git repositories. Secrets include keys, passwords, API tokens, and other sensitive information. Secrets exposed in this way must be treated as compromised and be replaced, which can be costly.

Business Impact

Increased risk of data breaches, financial loss, and reputational harm. Eroding customer trust and confidence.

Resources

Common

Incidence

How common is this issue?
7%1%
arrow down5%
lower

Exposure

How long do organizations remain exposed before fixing the problem?
2 years3 months
arrow down89%
shorter
BenchmarkWith Clayton

Frameworks

TrustediconSecureiconData SecurityiconUse of EncryptioniconA02:2021 – Cryptographic Failuresicon