← Inspection rules

SEC-004 / v1.2.0 / 2026-10-02

Inspect artifacts and attachments for secret inclusion

Editorial inspection guidance. Start with read-only permissions; fixes, credential revocation, and production changes follow the owner’s authorization.

Applicability

Environments storing or distributing code, artifacts, containers, or support material.

Where to look first

  • Visibility settings, Git history, distribution artifacts
  • Dockerfiles, image layers, CI logs, attachment procedures

Inspection steps

  1. Use authorized scanners; record only location and type, never secret values or whole environments.
  2. Check Git history and image layers as well as the final filesystem.

Remediation direction

  • Use build-time secret mechanisms and sanitization. Verify revocation of leaked keys with SEC-005.

Evidence required for completion

  • Record synthetic-secret test results and the coverage of artifact inspection.

Limits and unverified scope

  • Secret-file access follows owner permissions. Deletion of all external copies cannot be established.