Sensitive information in comments

Sensitive information in comments

Description

Passwords, tokens, API keys and internal connection details left in comments may be exposed through repositories, packages or deployment artifacts.

Potential impact

  • Exposed secrets may enable access to accounts or internal services.
  • Values in repository history may remain usable after the current code is edited.

Remediation

  • Remove actual secrets and internal connection details from comments.
  • Revoke exposed secrets and replace them with new values, then consider repository-history cleanup. Deleting history cannot recall copies already obtained.

Examples

Before

javascript
// password = "prod-db-password"

After

javascript
// password is loaded from the secret manager at runtime

Explanation:

  • Before: Operational secrets in comments can be exposed with the source or distributed artifacts.
  • After: The comment describes how to obtain the value instead of containing the password, token, key or internal address itself.

References