By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Google Veles is a New Open-source Secret Scanner Powering GCP
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > Google Veles is a New Open-source Secret Scanner Powering GCP
News

Google Veles is a New Open-source Secret Scanner Powering GCP

News Room
Last updated: 2025/08/25 at 5:42 AM
News Room Published 25 August 2025
Share
SHARE

Google Veles is a newly released open-source secret scanner, launched as part of Google’s broader OSV-SCALIBR (Software Composition Analysis LIBRary) ecosystem. Veles integrates seamlessly with other OSV-SCALIBR tools and also powers secret scanning in Google Cloud, while remaining available as a standalone module.

Veles is designed to detect unintended exposure of sensitive credentials across your organization’s internal systems. It helps you find secrets where they don’t belong, so you can prevent them from being abused.

Google will use Veles as the secret scanner for Google Cloud products, including Artifact Registry and Security Command Center (SCC). By integrating Veles into SCC, Google aims to support both shift-left and shift-right security approaches, which means scanning for secrets not only at the infrastructure level but also across Compute Engine and GKE.

Google also says their open source security team is using Veles to scan hundreds of millions of open-source artifacts. The company emphasizes that, while GitHub, GitLab, and other similar services do a great job scanning public source code, the risk of inadvertently exposing credentials extends well beyond that, for example into package registries, build artifacts, container images, and other distribution channels where secrets can accidentally leak.

Built packages and Docker images often include configuration, compiled binaries, and build scripts, all potential sources of leaked credentials. Publishing these artifacts on open-source repositories like Maven Central, PyPI, or DockerHub can expose leaked credentials to exploitation.

Google says it has already seen significant results from using Veles, successfully identifying and reporting exposed credentials such as API keys, service account keys, and OAuth client secrets across large volumes of historical artifacts.

Veles is implemented as a Go library, allowing developers to directly integrate its API and scan for secrets using the DetectionEngine class. Alternatively, you can use it through osv-scalibur, a Python package, using the osv_scalibr.scan command.

In its current release, Veles only supports Google Cloud Platform (GCP) API Keys, GCP Service Account Keys, and RubyGems API Keys. Google says Veles has been designed to make it easy to add new detector and validator types and they plan to extend the tool to include support for other secret types over time. According to Google engineers, the long-term goal is for Veles to cover hundreds or even thousands of credential types.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article IBM and NASA Develop a Digital Twin of the Sun to Predict Future Solar Storms
Next Article Transparent Tribe Targets Indian Govt With Weaponized Desktop Shortcuts via Phishing
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

How to manage multiple Instagram accounts (without losing your mind)
Computing
How I unleash the power of Google Keep to save my life from utter chaos
News
Our favorite smart lock is on sale for the first time today
News
Meet Augment Code: HackerNoon Company of the Week | HackerNoon
Computing

You Might also Like

News

How I unleash the power of Google Keep to save my life from utter chaos

5 Min Read
News

Our favorite smart lock is on sale for the first time today

2 Min Read
News

Just bought a new Galaxy foldable? Watch out for this alert-hiding bug

2 Min Read
News

YouTube’s Weird Filters Are Making Shorts Look Worse

4 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?