The key somebody pasted in two years ago still works.
Credentials in your code and in what your app sends to the browser, found in what you ship today and in every version behind it, then checked for whether they still open anything.

In the code, and in what the browser receives.
What reaches the list, where a key leaks outside the repository, and what arrives when one is found.
A list short enough to work through.
Identifiers and hashes look random too, which is why scanners that score strings on randomness bury the real one. Judging a string by how it is built leaves the report with the credential and not much else.
- Placeholders and fixtures judged by what surrounds them
- Cloud keys, database URLs, private keys, tokens and CI credentials

The key your frontend hands to every visitor.
A key bundled into your JavaScript is public the moment the page loads: anyone can open the browser's developer tools and read it. The run checks what your live application actually serves, not only the repository behind it.
- Found in the running app, not just the code
- Keys that belong on a server, flagged when the browser gets them
What arrives when one is found.
The file and the line, with the code around it, so it is confirmed at a glance. What it reaches, because a read-only test key and a production write key are not the same finding. And how far back it goes, which decides whether rotating is enough.
- The value itself is masked, never stored
- Assign it, link a ticket, and track it to closed

Anyone with the repository can sign tokens the service accepts, so they can mint a session for any user. The key stays compromised after it is removed from the current tree.
Deleting the line does not remove the secret.
Today's code
Keys written into source, config and environment files — including the local fallback that quietly became the production value.
Every version behind it
The whole history. A secret removed last year is still in the commit before it, and in every clone anyone took.
Where it is not obvious
Values hidden behind a layer of encoding, and credentials sitting inside committed archives and build artefacts.
Questions about secret detection.
Find out what is already in your history.
Connect a repository and the first run reads every version behind what you ship today.
