Uploaded image for project: 'Project Quay'
  1. Project Quay
  2. PROJQUAY-9221

Implement automated secret-scrubbing in CI/CD pipelines to prevent credential leaks in logs.

XMLWordPrintable

    • Icon: Task Task
    • Resolution: Can't Do
    • Icon: Critical Critical
    • None
    • None
    • quay.io
    • False
    • Hide

      None

      Show
      None
    • False

      *Issue:* An audit revealed that deployment scripts occasionally log configuration file snippets to CI/CD job logs, creating a high risk of accidental secret exposure.
      *Corrective Action:* Integrate a secret-scrubbing tool into the CI/CD runner environment. This tool will automatically scan all log outputs for patterns matching known secret formats and mask them before they are saved.
      *Result:* This action will significantly lower the risk of sensitive credentials being exposed in build and deployment logs.

              Unassigned Unassigned
              doconnor@redhat.com Dave O'Connor
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: