Skip to main content

Secret Detection Results Viewer

To view Secret Detection scan results:

  1. Go to the Workspace Workspace.png > Projects page and hover over the Results button for the desired project.

  2. Select the SCS scanner.

    Image_2082.png

    The SCS results viewer opens with Secret Detection selected for display.

Viewing Secret Detection Results

When the Secret Detection scanner is selected in the SCS results viewer, results are grouped by the type of secret detected. When you click on a type, a list of risks of that type is shown.

Image_1258.png

The following table describes the information shown for each risk.

Item

Description

Severity

The severity of the risk.

Tip

The severity for detected secrets is generally set as High. However, when the validity test is run (i.e. for supported secret types), valid secrets are set as Critical and invalid secrets are set as Medium.

File/Artifact

The path to the file or artifact in which the secret was detected.

Location

The line in which the secret was detected.

Validity

Indicates whether or not the secret is currently valid.

Remediation

Shows a few characters of the detected secret, with the remaining characters masked for security purposes. The recommended remediation for detected secrets is to first remove the secret from your file and then to change the secret.