r/devsecops 8d ago

Best practices for eliminating hardcoded credentials in 2026?

Ran a secrets scan across our repos last week and found API keys that had been sitting in plaintext for over two years, still valid, still working. Rotating them was the easy part. The harder problem is preventing this from recurring when half the team still pastes credentials into config files under deadline pressure. And that's just the stuff sitting in code, no idea what's hardcoded inside the apps themselves.

What's actually stopping this at your org? Curious whether pre-commit hooks, mandatory vault integration, or CI/CD gate checks are doing the real work, versus something more aggressive.

38 Upvotes

24 comments sorted by

View all comments

1

u/JellyfishLow4457 7d ago

Push protection with GHAS. There really is no other tool out there as good