Home / Companies / Cloudsmith / Blog / Post Details
Content Deep Dive

OWASP CI/CD Part 6: Insufficient Credential Hygiene

Blog post from Cloudsmith

Post Details
Company
Date Published
Author
Nigel Douglas
Word Count
1,194
Company Posts That Month
9
Language
English
Hacker News Points
-
Post removed?
No
Summary

CI/CD systems heavily rely on credentials to operate, but poorly managed or overly permissive credentials can create a complex web of access points that become prime targets for attackers. Common risks associated with insufficient credential hygiene include secrets being accidentally committed to code, overly-permissive credentials in pipelines, secrets embedded in container image layers, secrets printed to build logs, and unrotated, long-lived credentials. Real-world breaches caused by poor credential hygiene have been documented, such as the 2021 Travis CI security issue and Uber's two major breaches tied to credential mismanagement. To mitigate these risks, organizations must adopt a proactive and layered approach to secrets management, including mapping the credential landscape, classifying secrets by sensitivity and exposure risk, preferring ephemeral credentials, restricting credential usage context, preventing secret leaks in code, securing console output, and cleaning artifacts thoroughly.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 32 1,395 210 85 +3%
Kubernetes 1 2,191 312 96 +14%
Observability 1 2,164 505 155 +14%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.