GitLab
Security & compliance
Active leaked secrets
Part of the GitLab scanner findings check · fix arrives as a guide
What it is
GitLab secret detection has found an active credential in the repository.
Why it matters
The credential is in history and readable by everyone with project access. Detection confirms it exists; it does not do anything about it still being valid.
How to fix it
Rotate the credential immediately, then remove it from the code and enable secret push protection. Review the provider's audit log for use you did not authorise. The vulnerability report this reads is a GitLab Ultimate feature, and only holds data once the scanners have run in a pipeline.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.