You install their Github app and give them access to your Github repo (private repos are ok too) and they run a Github workflow when each PR is submitted scanning for secrets that should not be in the code. Really happy with how their product works.
If you weren't aware of it... There is a world of static application security tools (SAST) which can help you. Add them to your text editor/ci/cd to use them.
UltraMagnus|4 months ago
You install their Github app and give them access to your Github repo (private repos are ok too) and they run a Github workflow when each PR is submitted scanning for secrets that should not be in the code. Really happy with how their product works.
unsungNovelty|4 months ago
https://owasp.org/www-community/Source_Code_Analysis_Tools
EatonZ|4 months ago
I worked for them a little bit and their product is really impressive and works great.
heretoread9000|4 months ago
vivzkestrel|4 months ago
richbell|4 months ago