| Prevention |
.gitignore, pre-commit hooks, CI platform secrets, OIDC |
| Detection |
GitHub secret scanning, gitleaks, truffleHog, CI scanning |
| Management |
AWS Secrets Manager, Vault, External Secrets Operator |
| Rotation |
Automated rotation, dynamic secrets, short-lived credentials |
| Response |
Revoke, assess blast radius, audit logs, post-mortem |