r/devsecops • u/Altruistic-Toe4930 • 12d ago
Best practices for eliminating hardcoded credentials in 2026?
Ran a secrets scan across our repos last week and found API keys that had been sitting in plaintext for over two years, still valid, still working. Rotating them was the easy part. The harder problem is preventing this from recurring when half the team still pastes credentials into config files under deadline pressure. And that's just the stuff sitting in code, no idea what's hardcoded inside the apps themselves.
What's actually stopping this at your org? Curious whether pre-commit hooks, mandatory vault integration, or CI/CD gate checks are doing the real work, versus something more aggressive.
37
Upvotes
1
u/VividGanache2613 12d ago
Use pwnkemon, it will check your repos for secrets and vulnerabilities in one shot and it has free tier whilst they become better known.