Research scanning 5 million applications uncovered over 42,000 exposed secrets in JavaScript bundles, revealing critical gaps in traditional security tools. SAST, DAST, and infrastructure scanners often miss secrets embedded in front-end JavaScript files because they don't spider single-page applications or scan bundled assets.
Table of contents
Established secrets detection methods (and their limitations) #Building a secrets detection check for JavaScript bundles #What we found #Don't ship your secrets #Sort: