DiscoverThe Open Source WayCredential Digger – detecting leaked secrets on GitHub
Credential Digger – detecting leaked secrets on GitHub

Credential Digger – detecting leaked secrets on GitHub

Update: 2023-06-28
Share

Description

Credential Digger is an SAP Open-Source code scanner for detecting hardcoded secrets. In this episode, Slim Trabelsi discusses with host Karsten Hohage what led to the creation of Credential Digger and about its key differentiators. Slim also speaks of the early challenges of scanning for secrets, and lists the many advantages of using open source for building and maintaining Credential Digger. Open source comes with visibility for customers, and contributors can work on a project even before they join the team or after they leave, leading to improved continuity and a better tool overall.









Guests:





<figure class="alignright size-full"></figure>



Slim Trabelsi joined SAP 15 years ago and currently works as a senior security expert in the SAP Security Research team. His background includes data privacy, data protection, and social media security. He is currently focusing his research activities on cyber security, threat intelligence, and surveillance. Slim recently developed an open-source tool called Credential Digger, which is used to identify hardcoded secrets in source code repositories like GitHub.  













Show Notes:





















Hosted by Karsten Hohage – Product Expert in Technology and Innovation (T&I)





<figure class="alignleft" id="block-270fb938-6e73-43ba-890d-53b619616749">This image has an empty alt attribute; its file name is Karsten-Hohage.jpeg</figure>



LinkedIn: https://www.linkedin.com/in/karsten-hohage-0180312/









The post Credential Digger – detecting leaked secrets on GitHub first appeared on The Open Source Way.

Comments 
loading
00:00
00:00
1.0x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Credential Digger – detecting leaked secrets on GitHub

Credential Digger – detecting leaked secrets on GitHub

SAP SE