Paris, France
2017
  |  By Guardians
Cursor, Claude Code, and GitHub Copilot leave credentials scattered across config files, logs, and shell history that repository and CI scanners never see. Here's where that trail actually lives, and how to close it.
  |  By Dwayne McDaniel
Docker Sandboxes isolate AI coding agents from the host. The GitGuardian Mixin Kit adds ggshield and AI hooks to scan prompts, tool actions, and outputs for secrets, giving developers a safer, repeatable path for agentic coding.
  |  By Gaetan Ferry
GitGuardian tested thousands of leaked GitHub App private keys and found 474 valid ones, some with admin access to entire organizations. CDC and BuildBuddy were among those affected. See the findings.
  |  By Katie DeMatteis
Recent campaigns show a consistent pattern: a supply chain attack compromises trusted software to reach the credentials held by developer machines and CI/CD pipelines.
  |  By Dwayne McDaniel
AI agents are only as autonomous as the credentials behind them. This article talks about the Cloud Security Alliance's autonomy framework, why an agent's intended boundaries rarely match its actual access, and how GitGuardian helps close that gap through detection, remediation, and prevention.
  |  By Dwayne McDaniel
A practical checklist for rotating service account credentials safely by assessing validity, leaks, permissions, consumers, vaults, copies, owners, and rollback.
  |  By Soujanya Ain
Leaked credentials now reach public sources faster than any security team can review them by hand. GitGuardian Public Secrets Monitoring runs agents over every public incident and returns a comprehensive verdict.
  |  By Dwayne McDaniel
Learn how the OWASP Top 10 CI/CD Security Risks map the modern software delivery attack surface, and why credential hygiene sits at the center of so many real-world failures.
  |  By Soujanya Ain
Antivirus and EDR catch malicious behavior on a machine. Neither tells you which valid credentials are exposed on it right now. That's credential security, a distinct job that finds exposed secrets and helps fix them before attackers do.
  |  By Dwayne McDaniel
S3 buckets have quietly become a credential blind spot: years of logs, backups, and pipeline output that nobody ever scans for secrets. In one 2025 incident (Sysdig), attackers reached admin access in eight minutes using IAM keys found in a public bucket.
  |  By GitGuardian
When AI agents during OpenAI's model training autonomously gained user admin rights on Hugging Face, organized on message boards, and escalated privileges, it signaled a permanent shift in cybersecurity. Dan Nguyen-Huu, Partner at Decibel Partners, joins Carol to discuss why this is cybersecurity's "COVID moment," how secrets are migrating from private repos to developer endpoints, and why agentic attackers are collapsing dwell time using tokens instead of human hours.
  |  By GitGuardian
An AI agent gained user admin rights on Hugging Face, and the agents organized on message boards, rebuilt them after takedowns, and escalated privileges on their own. Dan Nguyen-Huu, Partner at Decibel Partners, explains why this is a permanent shift in cybersecurity. "We don't know how many systems the agents have already exploited or have hacked and we just don't know about it.".
  |  By GitGuardian
GitGuardian's validity-override API lets security and engineering teams tell GitGuardian whether an exposed credential is actually valid, even when automatic checks mark it as Failed to Check. Secrets tied to internal services, private APIs, or systems GitGuardian cannot reach often fall into this category. GitGuardian automatically validates most supported credential types, but when it cannot, teams can now perform their own validation and feed the result back into the platform.
  |  By GitGuardian
A single compromised laptop can mean weeks of manual credential hunting, or hours of clear, prioritized action. See how GitGuardian Developer Endpoint Protection inventories every credential on a developer's machine so your security team can map the blast radius fast. When an attacker compromises a developer laptop, traditional endpoint tools cannot tell you what credentials were exposed.
  |  By GitGuardian
Every developer laptop is a credential store: secrets hide in.env files, config files, and shell history, and every AI agent on the machine keeps adding more. Most teams already scan repositories and CI pipelines for secrets, but a secret lands on the laptop long before it reaches either one, and that's the place nobody scans. GitGuardian's Developer Endpoint Protection closes that gap.
  |  By GitGuardian
ggshield v1.53.0 introduces ggshield machine setup, a consistent way to configure ggshield no matter how it was installed. Set up AI hooks for every detected AI coding assistant, install global git pre-commit/pre-push hooks, and deploy a honeytoken on the endpoint. You have full control, and we have options to customize which features you want to skip. This release also includes ggshield machine doctor, a read-only command that checks that the machine's ggshield protections are correctly set up, letting you know what steps to take if it encounters an issue.
  |  By GitGuardian
Your code repos aren't the only place secrets hide — your laptop is too. In this session, GitGuardian's Emanuelle Franquelin talks with CJ May, Cybersecurity Architect at Vermeer, about extending secrets detection beyond the codebase and onto developer endpoints. They dig into where credentials actually live on modern machines (think config files, shell history, and AI coding agents), why every workstation is fair game, and what to actually do once you find exposed secrets. Watch to see how one enterprise team is tackling credential sprawl to deploy AI safely.
  |  By GitGuardian
This white paper outlines our Secrets Management Maturity Model, a model to help your organization make sense of its actual posture and how to improve it.
  |  By GitGuardian
In this report from Forrester, you will learn how to get better at using Application Security Testing to heighten your developers' security senses.
  |  By GitGuardian
Discover Application Security solutions to further secure the SDLC by implementing automated secrets detection in the DevOps pipeline.
  |  By GitGuardian
In this document, we go beyond classical definitions of DevSecOps to express our vision of an emerging collaboration between Developers, AppSec, and Ops teams: the AppSec Shared Responsibility Model.

GitGuardian is the code security platform for the DevOps generation. With automated secrets detection and remediation, our platform enables Dev, Sec, and Ops to advance together towards the Secure Software Development Lifecycle.

Secure your software development lifecycle with enterprise-grade secrets detection. Eliminate blind spots with our automated, battle-tested detection engine:

  • There’s no secret we can’t find: With hundreds of built-in secret detectors scanning thousands of git repositories, GitGuardian brings everything to light. Build custom detectors to enhance your scans for secrets unique to your organization.
  • Precise, real-time detection without the hassle: High-efficiency detection proven by billions of commits. GitGuardian is fast, robust, and battle-tested — we’ve scanned over 3 billion commits pushed to public GitHub repositories since 2018.
  • Remediation in hours, not days: GitGuardian unites developer and security teams with cross-functional data for in-depth investigation and remediation. Enable shift-left testing using your existing systems, teams, and processes.

Keep secrets out of your source code.