---
id: secrets
requestedLanguage: en
descriptionLanguage: en
---

# Secret Scanning

- Type: security testing technique
- Group: Security
- Placement: Security
- [Source](<https://devguide.owasp.org/en/04-design/02-web-app-checklist/08-protect-data/>)

[HTML](https://dpm.cnonim.name/practices/secrets/)

Find accidentally committed keys, tokens, and other secrets in code and artifacts; exposed active secrets must be revoked.

## Relationships

- may run within: [Continuous Integration](/practices/ci/en.md) (support)
- checks some rules from: [Secure Coding Practices](/practices/securecoding/en.md) (verification)

[Show on the map](https://dpm.cnonim.name/#practice=secrets&lang=en)
