> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/credential-hygiene/appsec-cicd-75.md).

# Accesses to cloud providers using insecure long-term credentials

## Rule Details

|                       |                    |
| --------------------- | ------------------ |
| Cortex AppSec Rule ID | APPSEC\_CICD\_75   |
| Category              | Credential Hygiene |
| Severity              | MEDIUM             |

## Impact

Long-term credentials used by automated workflows to authenticate to cloud or external services are stored as secrets in the repository. This increases the potential impact of credential theft, as stolen credentials can be used long after a workflow run is complete. In some platforms, it may not be possible to restrict access to stored secrets based on branch protections. Any user with sufficient permissions to modify repository code could potentially expose these secrets.

## Recommended Solution - Buildtime

Since October 2021, GitHub supports the OIDC (OpenID Connect) authentication protocol to replace long-term credentials with short-lived access tokens. Using OIDC, the GitHub Actions workflow can request a short-lived token directly from the cloud provider, which expires automatically as the workflow run ends. In addition, OIDC allows more granular control over how secrets can be used. For example, it is possible to filter access to tokens when the request originates in specific protected branches or environments. For more information about using OIDC in GitHub refer to: <https://docs.github.com/en/actions/deployment/security-hardening-your-deployments/about-security-hardening-with-openid-connect>.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/appsec-rules/ci-cd-security/credential-hygiene/appsec-cicd-75.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
