Secrets & configuration

Catch exposed credentials and unsafe configuration before release.

Security mistakes often sit beside the application: a credential committed to a configuration file, an overly permissive infrastructure definition or a risky build setting. Code Security brings these surfaces into the repository review so engineers can fix the source of the configuration and track the change with the rest of their code.

Review the files around the application
  • src/Source and credential candidates
  • infra/Infrastructure definitions
  • DockerfileContainer build settings
  • .github/workflows/Supported delivery configuration

Illustrative repository. Actual coverage follows recognised files, selected checks and the installed rule bundle.

01 / Secrets & configuration

Find a possible secret without distributing the secret

Secret review looks for supported credential patterns and sensitive values in available source and configuration. Results connect the candidate to its location so the owner can investigate. Secret values are excluded from uploads, and output redaction helps keep the review from becoming another copy of the credential.

A match is not a live credential test. Confirm whether the value is real through your own approved process. If a credential was exposed, removing it from a file is only one step: rotation, access review and checking relevant history may also be needed.

02 / Secrets & configuration

Review infrastructure where changes are made

Supported configuration families include infrastructure definitions, container files, Kubernetes resources, workflow files and templates. Checks focus on security-relevant settings in those files, with language and family coverage published in the coverage reference.

Repository analysis cannot tell you whether a cloud administrator changed a setting after deployment. Use it to review the proposed configuration and keep live environment validation in the operating workflow. Build-time variable substitution, external modules and runtime defaults can affect the final behaviour.

03 / Secrets & configuration

Give the engineer a correction they can verify

Keep the finding next to the configuration path and the intended change. The engineer can review a narrower permission, correct a secret reference or change a container setting, then rerun the scanner and the relevant infrastructure or application checks.

The same optional-upload model applies here as it does to source findings. Organisations can review configuration risk centrally without uploading an entire repository. Source snippets remain an explicit choice and should be checked for sensitive content before they are shared.

Reviewable output

The information behind the next decision.

Review source, infrastructure definitions and delivery configuration locally, with redacted secret findings and file-level context.

Repository surfaces and the next review step
SurfaceReview focusWhat remains outside the scan
SecretsPossible credentials and sensitive valuesLive validity, account activity and credential rotation
Infrastructure definitionsSecurity-relevant permissions and configurationThe currently deployed cloud state
Containers and orchestrationSupported build and workload settingsAll runtime behaviour and externally supplied settings
Delivery workflowsSupported CI and repository configuration patternsHosted branch protection and organisation permissions

Put it to work

Start with one representative repository.

  1. Bring the supporting files into scope

    Run the selected checks on the repository root used by the team, including recognised build and infrastructure definitions.

  2. Triage without spreading credentials

    Inspect the redacted finding and restricted source location. Follow your credential response process for confirmed exposure.

  3. Correct and verify

    Commit the configuration change, run appropriate tests, and rescan the revision used for release.

Review the repository's supporting files
magdox scan --secrets .
magdox scan --full .
magdox scan --show-payload --repository customer-api .

The payload preview prevents upload and redacts sensitive values; it is not the exact transmitted body. Treat file paths and other metadata as potentially sensitive too.

Configuration and command reference

Before you start

Scope and practical questions.

Will Magdox try the credentials it detects?

No live credential validation is promised. A finding is a candidate for your authorised investigation, not permission to use the value.

Is this cloud posture management?

These checks examine repository configuration. They do not continuously inventory or validate the deployed cloud account.

Code Security · next step

Evaluate the workflow on your own code.

Use a repository your team understands, review the findings with its engineers and decide how the result fits your delivery process.

14-day self-service trial. Card required; cancel before the trial ends to avoid the first charge.