DEV Community

Cover image for Detecting credentials in source code: open-source or commercial solutions?

Detecting credentials in source code: open-source or commercial solutions?

Mackenzie on November 24, 2020

In modern software development we rely on hundreds, sometimes thousands of different building blocks. The glue that connects all the different buil...
Collapse
 
v6 profile image
πŸ¦„N BπŸ›‘

Wow, what a great resource!

Thank you for including links to additional resources.

Might I request an update for examples that give some context to this, perhaps on how to set this up as part of a static code analysis pipeline, with CheckMarkX or Fortify, and with SonarQube?

If I make such a post, I'll include a link to yours.

This has become a big deal in my line of work.

Collapse
 
advocatemack profile image
Mackenzie

This sounds awesome. Maybe we can collab on a followup discussing other vulnerabilities and tools?
If not, sounds like a fun topic for my next post. Appreciate the comment.

Collapse
 
maxivanov profile image
Max Ivanov

Comprehensive breakdown! Bookmarked.

Collapse
 
keogami profile image
keogami

Would love it if you could add examples for what a "secret" might look like
Neat resource tho XD cheers