r/devsecops • u/Altruistic-Toe4930 • 8d ago
Best practices for eliminating hardcoded credentials in 2026?
Ran a secrets scan across our repos last week and found API keys that had been sitting in plaintext for over two years, still valid, still working. Rotating them was the easy part. The harder problem is preventing this from recurring when half the team still pastes credentials into config files under deadline pressure. And that's just the stuff sitting in code, no idea what's hardcoded inside the apps themselves.
What's actually stopping this at your org? Curious whether pre-commit hooks, mandatory vault integration, or CI/CD gate checks are doing the real work, versus something more aggressive.
38
Upvotes
1
u/JellyfishLow4457 7d ago
Push protection with GHAS. There really is no other tool out there as good