Assets

Use the Assets page to overview, filter, and sort your assets. And, if applicable, see helpful information about IaC data in each asset.

If your asset has any IaC issues, you can find the IaC tag on that asset, and as top files with IaC issues (highest number of IaC issues).

To see the asset page:

  1. Click the name of an asset to expand it and see its findings.

  2. Click See all IaC issues or See exposed secrets to open the asset page that provides details about a single asset.

From the Dashboard, you can expand an asset to view issues. Click on an issue to see remediation instructions. Spectral classifies issues as code issues or infrastructure ("infra") issues. For secrets issues, SpectralOps tests the validity of keys. A live key or token is labeled as valid.

The Assets page includes these tabs:

  • Secrets - Shows the exposed secrets that Code Security found.

  • IaC - Shows the infrastructure-as-code issues that Code Security found in the asset grouped by file. Each IaC issue shows the IaC resource related to it.

  • CI/CD Hardening - Shows issues in the repository settings, for example, when the main or master branch has no policy for a merge.

  • Sprawl - Shows secrets that appear in multiple locations in an asset or across assets.