Skip to content
Published

Last reviewed: 2026-07-28

Secret detection

Find exposed secrets in connected repositories, rotate them safely, and manage ignores without pasting credentials into tickets.

Purpose

Secret detection highlights credentials and similar sensitive material discovered in the connected repository so you can revoke and replace them quickly.

Who

Security and platform owners triage findings. Developers rotate credentials in the systems that issued them. Triage, admins, and owners can ignore findings; members cannot.

Prerequisites

A connected repository with a secrets analysis unit, and core credits for scans that include secret detection.

How it works

  1. Run or refresh a scan that includes secrets for the intended commit.
  2. Open the secrets project unit and review each finding’s location and classification.
  3. Rotate or revoke the credential in the issuing system first.
  4. Remove or rewrite the offending content in git history only after rotation is complete, following your own VCS process.
  5. Re-scan the same project unit and commit context to confirm the exposure is gone.

Finding triage (ignore)

Prefer the narrowest ignore:

  • Occurrence — one finding location (or a selected set of N findings).
  • Entire rule / detector — every match of that rule in the project unit. Broader; use only when justified.

Rotate or revoke first. An ignore is a documented exception, not a deletion of history.

Business rules

Treat every finding as potentially valid until proven otherwise. Do not paste live secrets into CodeCleared comments, support tickets, chat, or exports. Finding ignores are not license overrides; see Overrides.

Scenarios & edge cases

Test fixture that looks real: prefer replacing fixtures with clearly fake values; if you must ignore, record owner and review date.

Secret already rotated: re-scan; an old commit may still show historical exposure on that commit.

Finding only on a feature branch: still rotate if the credential is real; branch isolation does not protect a leaked cloud key.

402 while other scans work: confirm core credits and that secret scanning is included in the requested scan types.

Limits

Detection reduces risk of unnoticed exposure; it cannot guarantee every secret format is recognized. History rewrites are outside CodeCleared’s product scope.

Common errors

  • Rotating nothing and only marking ignore.
  • Pasting the secret into a ticket “for context”.
  • Comparing results across different commits without recording which SHA was scanned.
  • Ignoring an entire rule when a single occurrence would suffice.

Links