FirstHack Learn
Log in Sign up free
Lessons in this course 0/6 All courses Secure Coding Practices

Cyber Security

Progress0 / 6 lessons
  1. 1. Never trust user input
  2. 2. SQL injection and parameterised queries
  3. 3. XSS and output encoding
  4. 4. Secrets management in code
  5. 5. Dependency and supply-chain hygiene
  6. 6. Logging and error handling without leaks

Courses › Secure Coding Practices

Secrets management in code

Keys out of the repository, into the environment, and what to do when one leaks.

12 min read · Lesson 4 of 6 · Pro

Why this one bites students hardest

You finish a project at 3 a.m., commit everything, push to a public GitHub repository so the examiner can see it. Inside config.py is a live API key for a payment sandbox, or a Firebase key, or an SMTP password.

Bots scan every new public commit on GitHub within seconds of the push. This is not a theoretical risk; it is an automated industry. Cloud keys are found and used for cryptocurrency mining fast enough that the first sign of trouble is a bill.

And the worst part: deleting the line in the next commit does not help. Git keeps history. The key stays in the repository forever, reachable by anyone who clones it.

What counts as a secret

The rest of this lesson is Pro

The free lessons of Secure Coding Practices finish what they start — read those first if you have not. This one goes further, and it is part of the paid half.

A pass opens the paid lessons of every course, the mock test papers and the company-wise series. It ends on its own date; nothing renews by itself.

Get a pass — from ₹29 for 7 days

Already bought one? Log in.