
Based on the OWASP ASVS assessment of the project, the security team identified that they were not meeting one of the authentication security requirements.

OWASP ASVS authentication: OWASP ASVS authentication verifies that secrets, API keys, and passwords are not included in the source code, or in online source code repositories.

The security team further investigated the existing practices of secrets management. The CTO, Richard, clarified that the issue was becoming a headache for both the development and operation team. In the development and testing environment, developers may keep the password or keys in a separate configuration file. However, to filter these files and to separate them in a different version controls ...

Get Hands-On Security in DevOps now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.