What Challenges Do Developers Face About Checked-in Secrets in Software Artifacts?
Setu Kumar Basak, Lorenzo Neil, Bradley Reaves, Laurie A. Williams
Abstract
Throughout 2021, GitGuardian's monitoring of public GitHub repositories revealed a two-fold increase in the number of secrets (database credentials, API keys, and other credentials) exposed compared to 2020, accumulating more than six million secrets. To our knowledge, the challenges developers face to avoid checked-in secrets are not yet characterized. The goal of our paper is to aid researchers and tool developers in understanding and prioritizing opportunities for future research and tool automation for mitigating checked-in secrets through an empirical investigation of challenges and solutions related to checked-in secrets. We extract 779 questions related to checked-in secrets on Stack Exchange and apply qualitative analysis to determine the challenges and the solutions posed by others for each of the challenges. We identify 27 challenges and 13 solutions. The four most common challenges, in ranked order, are: (i) store/version of secrets during deployment; (ii) store/version of secrets in source code; (iii) ignore/hide of secrets in source code; and (iv) sanitize VCS history. The three most common solutions, in ranked order, are: (i) move secrets out of source code/version control and use template config file; (ii) secret management in deployment; and (iii) use local environment variables. Our findings indicate that the same solution has been mentioned to mitigate multiple challenges. However, our findings also identify an increasing trend in questions lacking accepted solutions substantiating the need for future research and tool automation on managing secrets.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4b68b043-1f9f-4044-92fd-1c900baa4cfcCited by top-tier papers2
- AssetHarvester: A Static Analysis Tool for Detecting Secret-Asset Pairs in Software ArtifactsSetu Kumar Basak, K. Virgil English, Ken Ogura, Vitesh Kambara et al.ICSE 2025 · 1 citation
- The File That Contained the Keys Has Been Removed: An Empirical Analysis of Secret Leaks in Cloud Buckets and Responsible Disclosure OutcomesSoufian El Yadmani, Olga Gadyatskaya, Yury ZhauniarovichS&P 2025
Builds on2
Related papers
- Pushed by Accident: A Mixed-Methods Study on Strategies of Handling Secret Information in Source Code RepositoriesAlexander Krause, Jan H. Klemmer, Nicolas Huaman, Dominik Wermke et al.USENIX Security 2023
- Leaky Apps: Large-scale Analysis of Secrets Distributed in Android and iOS AppsDavid Schmidt, Sebastian Schrittwieser, Edgar R. WeipplCCS 2025
- Altered Histories in Version Control System Repositories: Evidence from the TrenchesSolal Rapaport, Laurent Pautet, Samuel Tardieu, Stefano ZacchiroliASE 2025
- How do Developers Talk about GitHub Actions? Evidence from Online Software Development CommunityYang Zhang, Yiwen Wu, Tingting Chen, Tao Wang et al.ICSE 2024 · 12 citations
- Hey, Your Secrets Leaked! Detecting and Characterizing Secret Leakage in the WildJiawei Zhou, Zidong Zhang, Lingyun Ying, Huajun Chai et al.S&P 2025
