Skip to content

Scope, fee and working days are published on every engagement

CorePhysix Labs Technology lab

Specification SEC·105

SEC · Security & Compliance Defined scope Fixed fee

Secrets and Dependency Hygiene Sprint

Committed credentials found and rotated, vulnerable packages mapped, and scanning added so secrets stop reaching your repositories.

Fee · GST incl.
₹12,999
Duration
6 working days
Deliverables
7

01 Overview

A repository that has never been scanned can hold a working credential deep in its history, and deleting the file does not remove it from earlier commits. We scan the full history, check which of the secrets found are still valid, and help you rotate them in an order that avoids outages. We also deal with dependency hygiene: outdated packages with known vulnerabilities, an upgrade path that will not swallow a month, and automated scanning that catches the next problem at the pull request.

02 Deliverables

7 items

What you receive at handover

  1. D01 Secret scan of the full git history across up to 20 repositories
  2. D02 Confirmed list of still-valid credentials, ranked in the order they should be rotated
  3. D03 Secrets moved into a manager such as AWS Secrets Manager or Doppler
  4. D04 Report on vulnerable dependencies with an achievable order of upgrades
  5. D05 Pre-commit hooks and pipeline scanning that block new secret commits
  6. D06 Dependabot or Renovate set up with sensible rules for grouping updates
  7. D07 Short written guide to handling secrets for your team

03 Outcomes

What should be true once it ships

  • Working credentials are removed from places they should never have been stored
  • Vulnerable dependencies come with an upgrade order your team can realistically follow
  • New secret commits are blocked before they reach the remote repository

04 Process

How the 4 stages run

  1. Scan Repository history and active branches are searched for credentials
  2. Verify Each finding is tested to confirm whether it still works
  3. Rotate Credentials are replaced in a sequence that avoids downtime
  4. Prevent Scanning, hooks and update automation are put in place

05 Fit & inputs

A good fit for

  • Teams whose repository history has never been scanned
  • Businesses about to give contractors access to a private repository
  • Teams that have postponed dependency updates for a year or longer

What we need from you

  • Read access to every repository in scope, archived ones included
  • A person able to rotate credentials in each connected service
  • A short coordination window for rotating anything production-critical

These inputs are collected through the technical brief in your dashboard after payment. The duration is counted from when they arrive.

06 Answers

Questions about this engagement

Yes, but that rewrites history and disrupts every existing clone. Rotation is usually the better choice, and we explain why for your case.

Treat it as compromised and rotate it at once. We handle those on the first day.

Yes, including npm, Composer and PyPI mirrors, provided you give us access.

This is technology work delivered digitally — nothing is shipped. Work is delivered into systems you control within the duration stated above, and the delivery and refund policies set out what happens if a date is missed.

REL Related

Often considered alongside.

All Security & Compliance

Web Application VAPT

Manual penetration testing of your web application with evidence for each finding and a retest, so real risks are fixed and proven fixed.

Manual penetration test of authentication, authorisation and business logic

Fixed fee · GST incl.

₹29,999

Duration

12 working days

SOC 2 Evidence Groundwork

Technical controls and automated evidence collection for a SOC 2 Type II audit, operating before your observation window opens.

Control gap assessment against the Trust Services Criteria in scope

Fixed fee · GST incl.

₹44,999

Duration

30 working days

DPDP Act Readiness Review

A gap assessment against the DPDP Act, 2023 covering consent, retention, notices and breach handling, with a prioritised remediation plan.

Inventory of personal data held across your systems, vendors and storage locations

Fixed fee · GST incl.

₹22,999

Duration

15 working days

GST included

₹12,999

Next step

Have a system that needs building, fixing or securing?