Home / Companies / Snyk / Blog / Post Details
Content Deep Dive

Supply chain security incident at CircleCI: Rotate your secrets

Blog post from Snyk

Post Details
Company
Date Published
Author
Sonya Moisset and Vandana Verma Sehgal
Word Count
1,111
Company Posts That Month
13
Language
English
Hacker News Points
-
Post removed?
No
Summary

CircleCI disclosed a security incident on January 4 after evidence of a possible account intrusion emerged through an AWS CanaryToken alert, prompting the company to advise all customers to rotate secrets stored in project environment variables and contexts and review logs for suspicious access during the affected period. CircleCI also invalidated personal and project API tokens and rotated GitHub and Bitbucket OAuth tokens, while users were encouraged to inventory credentials, revoke rather than delete secrets, and rotate environment variables and SSH keys despite the potential disruption to CI/CD operations. The incident highlights risks posed by secret sprawl and long-lived static credentials, which can be difficult to track, may persist after services are retired, and can enable broader software supply-chain compromises if exposed. Recommended safeguards include encrypted secrets-management vaults, policy-controlled developer access, automated and regular rotation procedures, and dynamic short-lived credentials based on zero standing privileges, which limit permissions and reduce the usefulness of compromised keys.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 35 681 84 53 +116%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.