Does anyone know of a way to include the web.config / app.config security flagging? For example, I intentionally created a web.config file with fake user names and passwords. I also included various connection strings, etc. We ran a scan and it said all of those were fine. How is that? Putting sensitive information like that in either web/app config files is not a good thing. Shouldn’t SonarCloud detect that? If not, how can I get it to flag those? We are new to SonarCloud so perhaps we’re missing something but I searched and couldn’t find anyone else who was experiencing this. Thanks for reading.
Related topics
| Topic | Replies | Views | Activity | |
|---|---|---|---|---|
| Does SonarCloud Detect Secrets in .NET App Config Files? | 10 | 194 | October 13, 2025 | |
| Hardcoded secrets in Web.config not detected | 2 | 71 | August 28, 2025 | |
| Doubt about not detected hotspot in web.config about hardcoded credentials | 9 | 214 | November 25, 2024 | |
| Connection String and Notifications SonarCloud | 3 | 1143 | February 23, 2022 | |
| I'd like to add Hard-coded credentials are security-sensitive rule to JSON files | 2 | 1017 | April 4, 2022 |