Leaked secrets are a top breach vector. DevOps Shield secret-scanning templates run on every push and surface exposed credentials before they reach production.

How it works

  1. Enable the secret-scanning template for your repositories.
  2. Configure allow-lists for known test fixtures.
  3. Review detections and rotate any exposed secrets.
  4. Store rotated secrets in Azure Key Vault.
  5. Re-scan to confirm the leak is remediated.