Description
Passwords, tokens, API keys and internal connection details left in comments may be exposed through repositories, packages or deployment artifacts.
Potential impact
- Exposed secrets may enable access to accounts or internal services.
- Values in repository history may remain usable after the current code is edited.
Remediation
- Remove actual secrets and internal connection details from comments.
- Revoke exposed secrets and replace them with new values, then consider repository-history cleanup. Deleting history cannot recall copies already obtained.
Examples
Before
javascript
// password = "prod-db-password"
After
javascript
// password is loaded from the secret manager at runtime
Explanation:
- Before: Operational secrets in comments can be exposed with the source or distributed artifacts.
- After: The comment describes how to obtain the value instead of containing the password, token, key or internal address itself.