path holds secrets and every user on this server can read it
Any user or program on the server can read the secrets in this file.
sudo chmod 600 pathReferenceThe 22 checks
Security checksecrets-in-files
Environment files, Compose files and shell history in the folders listed under secrets.paths in /etc/kiyesi/config.yaml. Kiyesi reports where a secret is, never its value.
It needs root for part of what it reads. Other users' files and /root can be read only by root. Without root, that part is skipped and never counted as passed. Run sudo kiyesi scan to include it.
The report lists it as passed, in these words:
path holds secrets and every user on this server can read it
Any user or program on the server can read the secrets in this file.
sudo chmod 600 pathA secret is written into path at line line
Anyone who can read this file, or the repository it is in, has the secret. Keep secrets in an env file only the owner can read.
Move the value to an env file with chmod 600, and point env_file at it in pathA secret was typed into shell history in path at line line
Shell history is kept in plain text, so the secret stays on disk after the command ran.
Delete line line from path, then change the secret