Il-pipelines CI/CD għandhom bżonn sigriet (API keys, kredenzjali tad-deployment, passwords tad-database, tokens) biex ibnew u jiddeplojaw — imma l-immaniġġjar ta' dawn b'mod insigur huwa riskju serju. L-immaniġġjar xieraq tas-sigriet iżomm il-kredenzjali siguri matul il-pipeline.
Il-problema: is-sigriet għandhom qatt ma jkunu espos
Pipelines need credentials, but secrets are a major security risk if mishandled:
⚠️ NEVER hardcode secrets in code, pipeline config files, or commit them to Git
(committed secrets are exposed in history — even if "removed" later)
⚠️ NEVER print secrets in logs (pipeline logs may be visible/stored)
→ Leaked CI/CD secrets (deploy keys, cloud credentials) can compromise entire systems.
