{"id":90886,"date":"2024-02-21T07:00:00","date_gmt":"2024-02-21T12:00:00","guid":{"rendered":"https:\/\/staging.checkmarx.com\/?p=90886"},"modified":"2025-11-13T20:32:22","modified_gmt":"2025-11-13T18:32:22","slug":"how-to-prevent-secrets-from-leaking-out-of-your-dev-pipeline","status":"publish","type":"post","link":"https:\/\/checkmarx.com\/blog\/how-to-prevent-secrets-from-leaking-out-of-your-dev-pipeline\/","title":{"rendered":"How to Prevent Secrets from Leaking out of your Dev Pipeline\u00a0"},"content":{"rendered":"<p>Just as a homeowner might grapple with trying to find the source of a water leak, the challenge of identifying and plugging a leak in code, especially one involving &#8216;secrets&#8217; like login credentials, SSH Keys, API Keys, and AWS tokens can be just as frustrating for developers and cybersecurity professionals.&nbsp;<\/p>\n\n\n\n<p>There has been a recent uptick in leaks, most notably Mercedes-Benz and Football Australia, who found themselves as victims in incidents that highlight the need for robust data protection strategies.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-1\"><strong>The Mercedes-Benz Source Code Exposure<\/strong><\/h2>\n\n\n\n<p>Mercedes-Benz faced a significant breach when an employee inadvertently published a private authentication token on a public GitHub repository, granting unfettered access to the company&#8217;s source code. This error was discovered by&nbsp;<a href=\"https:\/\/redhuntlabs.com\/\">RedHunt Labs<\/a>&nbsp;during a routine scan in January, revealing that the exposed token provided complete access to Mercedes&#8217;s GitHub Enterprise Server. This access level meant that anyone with the token could download private repositories containing sensitive data, including intellectual property, cloud access keys for Microsoft Azure and Amazon Web Services (AWS), database connection strings, and other critical internal information.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-2\"><strong>The Incident at Football Australia<\/strong><\/h2>\n\n\n\n<p><a href=\"https:\/\/cybernews.com\/security\/football-australia-leak-expose-players\/#:~:text=Australia's%20football%20governing%20body%2C%20Football,scored%20an%20%E2%80%9Cown%20goal.%E2%80%9D\">Cybernews researchers<\/a>&nbsp;reported a significant data leak at Football Australia, where personal information of Australian soccer players (including passports and contracts), as well as customer purchase details, were exposed online.&nbsp;The security breach&nbsp;lasted for at least 681 days and could&nbsp;potentially impact many local customers, with over 100 buckets of data exposed. The exposed data poses a severe threat, with potential for identity theft and fraud.<\/p>\n\n\n\n<p>This cybersecurity incident, attributed to human error, resulted from a leak of secrets from plain-text Amazon Web Services (AWS) keys. This allowed public access to 127 digital storage containers containing sensitive data.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/image-21-1.png\" alt=\"\" class=\"wp-image-95071\"><\/figure>\n\n\n\n<p class=\"has-text-align-center\"><em>Sample of the exposed data. Image by Cybernews.<\/em><\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-3\"><strong>Lessons Learned<\/strong><\/h2>\n\n\n\n<p>These incidents serve as potent reminders of the vulnerabilities inherent in digital infrastructures across all sectors. They highlight the need for:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\n<strong>Enhanced Secret Management:<\/strong>&nbsp;Employing tools and practices that ensure the secure handling of keys and tokens is non-negotiable.<\/li>\n\n\n\n<li>\n<strong>Regular Security Audits:<\/strong>&nbsp;Proactively scanning for vulnerabilities and exposures can prevent potential breaches.<\/li>\n\n\n\n<li>\n<strong>Education and Awareness:<\/strong>&nbsp;Human error being a common factor in both cases, underscores the importance of continuous education on best practices for all personnel involved in handling sensitive information.<\/li>\n\n\n\n<li>\n<strong>Incident Response Planning:<\/strong>&nbsp;Both organizations acted swiftly upon discovery, a testament to the importance of having an effective incident response strategy in place.<\/li>\n<\/ul>\n\n\n\n<p>The cybersecurity incidents faced by Football Australia and Mercedes-Benz illuminate the critical need for heightened security measures and vigilant management of digital assets. Let these stories be a rallying cry for a unified approach to protecting our digital world\u2014from the pitch to the pavement.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-4\"><strong>Maintaining the Sanctity of Secrets<\/strong><\/h2>\n\n\n\n<p>To avert the leakage of secrets, consider implementing these strategies:<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"1\">\n<li>\n<strong>Environment Variables for Secrets:<\/strong>&nbsp;Store secrets in environment variables rather than embedding them directly in code to facilitate easier management and prevent their accidental inclusion in version control.<\/li>\n\n\n\n<li>\n<strong>.gitignore for Sensitive Files:<\/strong>&nbsp;Utilize a .gitignore file to exclude files containing secrets from Git tracking. This ensures that these details do not inadvertently enter version control systems. If using environment variables for secrets, ensure their associated files are also ignored.<\/li>\n\n\n\n<li>\n<strong>Secrets Management Tools:<\/strong>&nbsp;Employ secrets management tools for the secure handling and storage of system or application secrets. This guarantees encryption and access solely to authorized individuals.<\/li>\n\n\n\n<li>\n<strong>Encryption of Secrets:<\/strong>&nbsp;Encrypt secrets prior to their storage in code repositories to add a security layer, making it challenging for attackers to obtain sensitive information.<\/li>\n\n\n\n<li>\n<strong>Two-Factor Authentication (2FA):<\/strong>&nbsp;Activate 2FA for access to code repositories, enhancing security and complicating unauthorized repository access efforts.<\/li>\n<\/ol>\n\n\n\n<p>These practices can significantly mitigate the risk of inadvertently exposing sensitive information across various platforms, including code repositories, content management systems, emails, and other digital assets not contained within a repository.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-5\"><strong>Preventing secrets from leaking on external tools with Secrets Detection by Checkmarx<\/strong><\/h2>\n\n\n\n<p>Secrets Detection integrates and expands deeper scanning capabilities of&nbsp;<strong>Too many secrets<\/strong>&nbsp;<a href=\"https:\/\/github.com\/Checkmarx\/2ms\">2MS<\/a>,&nbsp;a command line tool written in Go language and built over&nbsp;<a href=\"https:\/\/github.com\/gitleaks\/gitleaks\">gitleaks<\/a>, directly into Checkmarx One. 2MS is one of the most popular open-source tools for secret detection, with over 2 million downloads. Secrets Detection in Checkmarx One&nbsp;<code>f<\/code>inds secrets such as login credentials, API keys, SSH keys and more hidden in code, content systems, chat applications and more.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Supported tools include Confluence, Discord, filesystem, git, paligo, Slack, Git Hooks, GitHub Actions<\/li>\n\n\n\n<li>Scan history to ensure secrets are not leaked in any previous versions&nbsp;&nbsp;&nbsp;<\/li>\n\n\n\n<li>Detect secrets that are specific to your company with secret customization&nbsp;<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/image-22-1.png\" alt=\"\" class=\"wp-image-95072\"><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>Learn more about <a href=\"https:\/\/checkmarx.com\/blog\/secrets-secrets-are-no-fun-secrets-secrets-stored-in-plain-text-files-hurt-someone-2\/\">reducing the risk of leaked secrets<\/a> across the supply chain<\/p>","protected":false},"excerpt":{"rendered":"<p>Just as a homeowner might grapple with trying to find the source of a water leak, the challenge of identifying and plugging a leak in code, especially one involving &#8216;secrets&#8217; like login credentials, SSH Keys, API Keys, and AWS tokens can be just as frustrating for developers and cybersecurity professionals.&nbsp; There has been a recent [&hellip;]<\/p>\n","protected":false},"author":96,"featured_media":90890,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[85,84,1286,1296,1280],"tags":[86,87,190,385],"class_list":["post-90886","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-application-security-trends","category-blog","category-compliance-secure-sdlc-frameworks","category-secrets-detection","category-secure-coding-best-practices-for-developers","tag-application-security","tag-appsec","tag-english","tag-supply-chain-security"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.1.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>How to prevent secrets from leaking out of your dev pipeline\u00a0<\/title>\n<meta name=\"description\" content=\"Just as a homeowner might grapple with trying to find the source of a water leak, the challenge of identifying and plugging a leak in code, especially one involving &#039;secrets&#039; like login credentials, SSH Keys, API Keys, and AWS tokens can be just as frustrating for developers and cybersecurity professionals.\u00a0\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/checkmarx.com\/blog\/how-to-prevent-secrets-from-leaking-out-of-your-dev-pipeline\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How to prevent secrets from leaking out of your dev pipeline\u00a0\" \/>\n<meta property=\"og:description\" content=\"Just as a homeowner might grapple with trying to find the source of a water leak, the challenge of identifying and plugging a leak in code, especially one involving &#039;secrets&#039; like login credentials, SSH Keys, API Keys, and AWS tokens can be just as frustrating for developers and cybersecurity professionals.\u00a0\" \/>\n<meta property=\"og:url\" content=\"https:\/\/checkmarx.com\/blog\/how-to-prevent-secrets-from-leaking-out-of-your-dev-pipeline\/\" \/>\n<meta property=\"og:site_name\" content=\"Checkmarx\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis\" \/>\n<meta property=\"article:published_time\" content=\"2024-02-21T12:00:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-11-13T18:32:22+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/Aussie-Football.png\" \/>\n\t<meta property=\"og:image:width\" content=\"2134\" \/>\n\t<meta property=\"og:image:height\" content=\"1067\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Yohai West\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@checkmarx\" \/>\n<meta name=\"twitter:site\" content=\"@checkmarx\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Yohai West\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/checkmarx.com\/blog\/how-to-prevent-secrets-from-leaking-out-of-your-dev-pipeline\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/how-to-prevent-secrets-from-leaking-out-of-your-dev-pipeline\/\"},\"author\":{\"name\":\"Yohai West\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/8add2468c2941283a2c945d9a4dc2cf2\"},\"headline\":\"How to Prevent Secrets from Leaking out of your Dev Pipeline\u00a0\",\"datePublished\":\"2024-02-21T12:00:00+00:00\",\"dateModified\":\"2025-11-13T18:32:22+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/how-to-prevent-secrets-from-leaking-out-of-your-dev-pipeline\/\"},\"wordCount\":794,\"publisher\":{\"@id\":\"https:\/\/checkmarx.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/how-to-prevent-secrets-from-leaking-out-of-your-dev-pipeline\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/Aussie-Football.png\",\"keywords\":[\"Application Security\",\"AppSec\",\"English\",\"SSCS\"],\"articleSection\":[\"Application Security Trends &amp; Insights\",\"Blog\",\"Compliance &amp; Secure SDLC Frameworks\",\"Secrets Detection\",\"Secure Coding Best Practices for Developers\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/checkmarx.com\/blog\/how-to-prevent-secrets-from-leaking-out-of-your-dev-pipeline\/\",\"url\":\"https:\/\/checkmarx.com\/blog\/how-to-prevent-secrets-from-leaking-out-of-your-dev-pipeline\/\",\"name\":\"How to prevent secrets from leaking out of your dev pipeline\u00a0\",\"isPartOf\":{\"@id\":\"https:\/\/checkmarx.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/how-to-prevent-secrets-from-leaking-out-of-your-dev-pipeline\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/how-to-prevent-secrets-from-leaking-out-of-your-dev-pipeline\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/Aussie-Football.png\",\"datePublished\":\"2024-02-21T12:00:00+00:00\",\"dateModified\":\"2025-11-13T18:32:22+00:00\",\"description\":\"Just as a homeowner might grapple with trying to find the source of a water leak, the challenge of identifying and plugging a leak in code, especially one involving 'secrets' like login credentials, SSH Keys, API Keys, and AWS tokens can be just as frustrating for developers and cybersecurity professionals.\u00a0\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/checkmarx.com\/blog\/how-to-prevent-secrets-from-leaking-out-of-your-dev-pipeline\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/blog\/how-to-prevent-secrets-from-leaking-out-of-your-dev-pipeline\/#primaryimage\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/Aussie-Football.png\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/Aussie-Football.png\",\"width\":2134,\"height\":1067},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/checkmarx.com\/#website\",\"url\":\"https:\/\/checkmarx.com\/\",\"name\":\"Checkmarx\",\"description\":\"The world runs on code. We secure it.\",\"publisher\":{\"@id\":\"https:\/\/checkmarx.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/checkmarx.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/checkmarx.com\/#organization\",\"name\":\"Checkmarx\",\"url\":\"https:\/\/checkmarx.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg\",\"width\":1,\"height\":1,\"caption\":\"Checkmarx\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis\",\"https:\/\/x.com\/checkmarx\",\"https:\/\/www.youtube.com\/user\/CheckmarxResearchLab\",\"https:\/\/www.linkedin.com\/company\/checkmarx\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/8add2468c2941283a2c945d9a4dc2cf2\",\"name\":\"Yohai West\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/avatar_96.jpg\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/avatar_96.jpg\",\"caption\":\"Yohai West\"},\"url\":\"https:\/\/checkmarx.com\/author\/yochaiwest\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How to prevent secrets from leaking out of your dev pipeline\u00a0","description":"Just as a homeowner might grapple with trying to find the source of a water leak, the challenge of identifying and plugging a leak in code, especially one involving 'secrets' like login credentials, SSH Keys, API Keys, and AWS tokens can be just as frustrating for developers and cybersecurity professionals.\u00a0","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/checkmarx.com\/blog\/how-to-prevent-secrets-from-leaking-out-of-your-dev-pipeline\/","og_locale":"en_US","og_type":"article","og_title":"How to prevent secrets from leaking out of your dev pipeline\u00a0","og_description":"Just as a homeowner might grapple with trying to find the source of a water leak, the challenge of identifying and plugging a leak in code, especially one involving 'secrets' like login credentials, SSH Keys, API Keys, and AWS tokens can be just as frustrating for developers and cybersecurity professionals.\u00a0","og_url":"https:\/\/checkmarx.com\/blog\/how-to-prevent-secrets-from-leaking-out-of-your-dev-pipeline\/","og_site_name":"Checkmarx","article_publisher":"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis","article_published_time":"2024-02-21T12:00:00+00:00","article_modified_time":"2025-11-13T18:32:22+00:00","og_image":[{"width":2134,"height":1067,"url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/Aussie-Football.png","type":"image\/png"}],"author":"Yohai West","twitter_card":"summary_large_image","twitter_creator":"@checkmarx","twitter_site":"@checkmarx","twitter_misc":{"Written by":"Yohai West","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/checkmarx.com\/blog\/how-to-prevent-secrets-from-leaking-out-of-your-dev-pipeline\/#article","isPartOf":{"@id":"https:\/\/checkmarx.com\/blog\/how-to-prevent-secrets-from-leaking-out-of-your-dev-pipeline\/"},"author":{"name":"Yohai West","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/8add2468c2941283a2c945d9a4dc2cf2"},"headline":"How to Prevent Secrets from Leaking out of your Dev Pipeline\u00a0","datePublished":"2024-02-21T12:00:00+00:00","dateModified":"2025-11-13T18:32:22+00:00","mainEntityOfPage":{"@id":"https:\/\/checkmarx.com\/blog\/how-to-prevent-secrets-from-leaking-out-of-your-dev-pipeline\/"},"wordCount":794,"publisher":{"@id":"https:\/\/checkmarx.com\/#organization"},"image":{"@id":"https:\/\/checkmarx.com\/blog\/how-to-prevent-secrets-from-leaking-out-of-your-dev-pipeline\/#primaryimage"},"thumbnailUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/Aussie-Football.png","keywords":["Application Security","AppSec","English","SSCS"],"articleSection":["Application Security Trends &amp; Insights","Blog","Compliance &amp; Secure SDLC Frameworks","Secrets Detection","Secure Coding Best Practices for Developers"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/checkmarx.com\/blog\/how-to-prevent-secrets-from-leaking-out-of-your-dev-pipeline\/","url":"https:\/\/checkmarx.com\/blog\/how-to-prevent-secrets-from-leaking-out-of-your-dev-pipeline\/","name":"How to prevent secrets from leaking out of your dev pipeline\u00a0","isPartOf":{"@id":"https:\/\/checkmarx.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/checkmarx.com\/blog\/how-to-prevent-secrets-from-leaking-out-of-your-dev-pipeline\/#primaryimage"},"image":{"@id":"https:\/\/checkmarx.com\/blog\/how-to-prevent-secrets-from-leaking-out-of-your-dev-pipeline\/#primaryimage"},"thumbnailUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/Aussie-Football.png","datePublished":"2024-02-21T12:00:00+00:00","dateModified":"2025-11-13T18:32:22+00:00","description":"Just as a homeowner might grapple with trying to find the source of a water leak, the challenge of identifying and plugging a leak in code, especially one involving 'secrets' like login credentials, SSH Keys, API Keys, and AWS tokens can be just as frustrating for developers and cybersecurity professionals.\u00a0","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/checkmarx.com\/blog\/how-to-prevent-secrets-from-leaking-out-of-your-dev-pipeline\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/blog\/how-to-prevent-secrets-from-leaking-out-of-your-dev-pipeline\/#primaryimage","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/Aussie-Football.png","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/Aussie-Football.png","width":2134,"height":1067},{"@type":"WebSite","@id":"https:\/\/checkmarx.com\/#website","url":"https:\/\/checkmarx.com\/","name":"Checkmarx","description":"The world runs on code. We secure it.","publisher":{"@id":"https:\/\/checkmarx.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/checkmarx.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/checkmarx.com\/#organization","name":"Checkmarx","url":"https:\/\/checkmarx.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg","width":1,"height":1,"caption":"Checkmarx"},"image":{"@id":"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis","https:\/\/x.com\/checkmarx","https:\/\/www.youtube.com\/user\/CheckmarxResearchLab","https:\/\/www.linkedin.com\/company\/checkmarx"]},{"@type":"Person","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/8add2468c2941283a2c945d9a4dc2cf2","name":"Yohai West","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/image\/","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/avatar_96.jpg","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/avatar_96.jpg","caption":"Yohai West"},"url":"https:\/\/checkmarx.com\/author\/yochaiwest\/"}]}},"_links":{"self":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/posts\/90886","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/users\/96"}],"replies":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/comments?post=90886"}],"version-history":[{"count":0,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/posts\/90886\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/media\/90890"}],"wp:attachment":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/media?parent=90886"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/categories?post=90886"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/tags?post=90886"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}