Secret scanning

Scanning finds credentials in code and history. The number it finds says more about how you work than about how exposed you are.

A high count often means scanning has just been turned on and is surfacing years of accumulation. A low count may mean good practice or poor coverage. Either way, a finding is the beginning of the work: the credential has been exposed and needs replacing, not deleting.

Checked against the primary source.

More on Software supply chain & DevSecOps