Sensitive information in comments

Sensitive information is included in comments.

Description

Passwords, tokens, API keys or internal URLs left in comments can be exposed through repositories, packages or deployment artifacts.

Potential impact

  • Exposed secrets may allow accounts or internal services to be compromised.
  • Values retained in repository history may remain usable after the code is changed.

Remediation

  • Remove actual secrets and internal connection details from comments.
  • Revoke exposed secrets promptly and replace them with new values. Update consumers before considering repository-history cleanup. Cleaning history does not invalidate an exposed value.

Examples

Before

python
# password = "prod-db-password"

After

python
# password is loaded from the secret manager at runtime

Explanation:

  • Before: An operational secret is left in a comment that may be distributed with source or deployment artifacts.
  • After: The comment describes where the value comes from without containing the password, token, key or internal address itself.

References