पाठ 16 / 25
Secret Scanning on Every Patch
Never let a fix leak a credential.
Scan added lines before commit
Fixers sometimes paste credentials from logs, environment dumps or examples into code or test fixtures. Scan every added line for known key formats (cloud keys, private keys, tokens) and generic high-entropy secrets before the patch is committed or pushed, using tools such as gitleaks, trufflehog or GitHub secret scanning. Block the patch, and if a real secret was exposed anywhere, rotate it; removing it from the code is not enough.
Scanning a patch's added lines, run
I ran this with Python 3 (standard library) and, where it uses git, real git in a throwaway temporary repository. Candidate patches are written by hand to stand in for model output. Two of four added lines match: an API key assignment and an AWS access key id (the documented example key), so the patch is blocked. Real scanners use many more patterns plus entropy checks.
import re
PATTERNS = {"AWS key": r"AKIA[0-9A-Z]{16}", "private key": r"-----BEGIN [A-Z ]*PRIVATE KEY-----",
"generic token": r"(?i)(api[_-]?key|token|secret)\s*=\s*['\"][A-Za-z0-9_\-]{16,}['\"]"}
patch = """+DEBUG = False
+API_KEY = "sk_live_51HxQyZ2eX9vB7kLmN"
+client = Client(region="ap-south-1")
+AWS_ID = "AKIAIOSFODNN7EXAMPLE"
"""
added = [l[1:] for l in patch.splitlines() if l.startswith("+")]
hits = [(name, line.strip()) for line in added for name, p in PATTERNS.items() if re.search(p, line)]
for name, line in hits:
print(f"{name:<14} in added line: {line[:40]}")
print("patch blocked" if hits else "patch clean")
Output:
generic token in added line: API_KEY = "sk_live_51HxQyZ2eX9vB7kLmN" AWS key in added line: AWS_ID = "AKIAIOSFODNN7EXAMPLE" patch blocked
Keep secrets out of the fixer's view
Do not give the fixing agent production credentials or unredacted logs; it cannot leak what it never sees.
त्वरित जाँच: A real API key was committed and then removed in a later commit. What must also happen?
- Rename the variable
- Nothing, removal is enough
- Rotate the key, because it remains in history and may have been copied
- Make the repository bigger
Answer
Rotate the key, because it remains in history and may have been copied — Exposed secrets must be rotated.