Description
Passwords, tokens, API keys or internal URLs left in comments can be exposed through repositories, packages or deployment artifacts.
Potential impact
- Exposed secrets may allow accounts or internal services to be compromised.
- Values retained in repository history may remain usable after the code is changed.
Remediation
- Remove actual secrets and internal connection details from comments.
- Revoke exposed secrets promptly and replace them with new values. Update consumers before considering repository-history cleanup. Cleaning history does not invalidate an exposed value.
Examples
Before
python
# password = "prod-db-password"
After
python
# password is loaded from the secret manager at runtime
Explanation:
- Before: An operational secret is left in a comment that may be distributed with source or deployment artifacts.
- After: The comment describes where the value comes from without containing the password, token, key or internal address itself.