← Inspection rules
SEC-004 / v1.2.0 / 2026-10-02
Inspect artifacts and attachments for secret inclusion
Editorial inspection guidance. Start with read-only permissions; fixes, credential revocation, and production changes follow the owner’s authorization.
Applicability
Environments storing or distributing code, artifacts, containers, or support material.
Where to look first
- Visibility settings, Git history, distribution artifacts
- Dockerfiles, image layers, CI logs, attachment procedures
Inspection steps
- Use authorized scanners; record only location and type, never secret values or whole environments.
- Check Git history and image layers as well as the final filesystem.
Remediation direction
- Use build-time secret mechanisms and sanitization. Verify revocation of leaked keys with SEC-005.
Evidence required for completion
- Record synthetic-secret test results and the coverage of artifact inspection.
Limits and unverified scope
- Secret-file access follows owner permissions. Deletion of all external copies cannot be established.