Secrets & configuration
Catch exposed credentials and unsafe configuration before release.
Security mistakes often sit beside the application: a credential committed to a configuration file, an overly permissive infrastructure definition or a risky build setting. Code Security brings these surfaces into the repository review so engineers can fix the source of the configuration and track the change with the rest of their code.
src/Source and credential candidatesinfra/Infrastructure definitionsDockerfileContainer build settings.github/workflows/Supported delivery configuration
Illustrative repository. Actual coverage follows recognised files, selected checks and the installed rule bundle.
01 / Secrets & configuration
Find a possible secret without distributing the secret
Secret review looks for supported credential patterns and sensitive values in available source and configuration. Results connect the candidate to its location so the owner can investigate. Secret values are excluded from uploads, and output redaction helps keep the review from becoming another copy of the credential.
A match is not a live credential test. Confirm whether the value is real through your own approved process. If a credential was exposed, removing it from a file is only one step: rotation, access review and checking relevant history may also be needed.
02 / Secrets & configuration
Review infrastructure where changes are made
Supported configuration families include infrastructure definitions, container files, Kubernetes resources, workflow files and templates. Checks focus on security-relevant settings in those files, with language and family coverage published in the coverage reference.
Repository analysis cannot tell you whether a cloud administrator changed a setting after deployment. Use it to review the proposed configuration and keep live environment validation in the operating workflow. Build-time variable substitution, external modules and runtime defaults can affect the final behaviour.
03 / Secrets & configuration
Give the engineer a correction they can verify
Keep the finding next to the configuration path and the intended change. The engineer can review a narrower permission, correct a secret reference or change a container setting, then rerun the scanner and the relevant infrastructure or application checks.
The same optional-upload model applies here as it does to source findings. Organisations can review configuration risk centrally without uploading an entire repository. Source snippets remain an explicit choice and should be checked for sensitive content before they are shared.
Reviewable output
The information behind the next decision.
Review source, infrastructure definitions and delivery configuration locally, with redacted secret findings and file-level context.
| Surface | Review focus | What remains outside the scan |
|---|---|---|
| Secrets | Possible credentials and sensitive values | Live validity, account activity and credential rotation |
| Infrastructure definitions | Security-relevant permissions and configuration | The currently deployed cloud state |
| Containers and orchestration | Supported build and workload settings | All runtime behaviour and externally supplied settings |
| Delivery workflows | Supported CI and repository configuration patterns | Hosted branch protection and organisation permissions |
Put it to work
Start with one representative repository.
Bring the supporting files into scope
Run the selected checks on the repository root used by the team, including recognised build and infrastructure definitions.
Triage without spreading credentials
Inspect the redacted finding and restricted source location. Follow your credential response process for confirmed exposure.
Correct and verify
Commit the configuration change, run appropriate tests, and rescan the revision used for release.
magdox scan --secrets .
magdox scan --full .
magdox scan --show-payload --repository customer-api .The payload preview prevents upload and redacts sensitive values; it is not the exact transmitted body. Treat file paths and other metadata as potentially sensitive too.
Before you start
Scope and practical questions.
Will Magdox try the credentials it detects?
No live credential validation is promised. A finding is a candidate for your authorised investigation, not permission to use the value.
Is this cloud posture management?
These checks examine repository configuration. They do not continuously inventory or validate the deployed cloud account.
Explore Code Security
Source-code analysis
Local SAST with affected locations, supported flow evidence, severity, confidence and explicit analysis coverage.
Dependency security
Review known vulnerabilities, malicious-package indicators and unresolved dependency versions from the repository's own manifests and lockfiles.
Software, crypto & AI inventory
Build software, cryptographic and AI inventories locally, then find recognised components across the repositories you choose to upload.
Code Security · next step
Evaluate the workflow on your own code.
Use a repository your team understands, review the findings with its engineers and decide how the result fits your delivery process.
14-day self-service trial. Card required; cancel before the trial ends to avoid the first charge.