Build secrets should not become build artefacts
Secrets used during a build have a habit of ending up inside what the build produces.
Baked into a container layer, written to a config file, left in an intermediate image, captured in the manifest. Deleting them in a later step does not always remove them, because earlier layers persist. Anything published then carries the credential to whoever downloads it.
More on Software supply chain
- A trusted build can faithfully ship malicious sourceThe oven never reads the recipe
- Dependency confusion exploits naming and resolutionSame name, wrong shelf
- Typosquatting attacks developer attentionThe eye test you take at 2am
- Lockfiles improve repeatability, not eternal safetyAlways the same tin
- Transitive dependencies enlarge unseen trustOne handshake, a hundred guests
- Maintainer compromise can use the normal release channelIt came by the usual van
