Maine Street Partners

[ MSP.DD ] For investors and founders · Updated

Why check a target's code for leaked secrets?

Short answer

Because leaked keys stay valid for years. GitGuardian counted 23.8 million new secrets pushed to public GitHub in 2024, and 35% of the private repositories it scanned contained plaintext secrets. A key in the git history is exposed even if it was deleted from the latest version.

Why it matters

A leaked cloud, database or payment key can mean data exposure, fraud and regulatory fines after the deal closes, and the buyer owns the problem.

How to check

  1. 01Scan the full git history, not just the current files.
  2. 02Check whether any keys found are still active, and have them rotated before closing.
  3. 03Check how secrets are managed: a secrets manager, or environment files in the repository?
  4. 04Check CI logs and infrastructure configuration as well as application code.

Red flags

  • Live keys anywhere in the history.
  • Committed .env files.
  • One set of credentials shared by the whole team.

Good signs

  • A secrets manager in use.
  • Automated secret scanning on every push.

The numbers

  • GitGuardian counted 23.8 million new hardcoded secrets added to public GitHub repositories in 2024, a 25% rise on the year before. [1]
  • 35% of the private repositories in GitGuardian's customer research contained plaintext secrets. [1]
  • 70% of the secrets GitGuardian found leaked in 2022 were still active. [1]

Sources

  1. GitGuardian, The State of Secrets Sprawl 2025