← Back to VOLUME 15, ISSUE 9, SEPTEMBER 2026
This work is licensed under a Creative Commons Attribution 4.0 International License.
ARMOR: An Extensible Multi-Provider Secret Validation Framework for Automated Credential Verification in DevSecOps Pipelines
Siddharth Gupta, Poonam Bhartiya & Shailendra Shriwastava
π 1 viewπ₯ 1 download
Abstract: Credential leakage through public repositories creates an urgent incident-response problem: detection tools identify candidate secrets but do not establish whether a credential remains active. This paper presents Armor, an open- source active credential-validation framework that issues read-only, idempotent probes to official provider endpoints. Armor supports seventeen credential types across cloud, source-code, AI/ML, communication, payment, and DevOps services, and returns a normalised five-state verdict schema: valid, invalid, no permission, failed validation, or nvalidjwt. Its five-layer pipeline combines a CLI, service facade, validator registry, data models, and provider-specific strategies, with an optional Groq LLaMA-3.3-70B triage agent for unstructured text. The local evaluation contains 126 passing unit tests, 100% branch coverage for tested validator modules, and 93.55% total package coverage.
Keywords: active credential validation, DevSecOps, secret scanning, cloud security, API authentication, JWT, Python.
Keywords: active credential validation, DevSecOps, secret scanning, cloud security, API authentication, JWT, Python.
How to Cite:
[1] Siddharth Gupta, Poonam Bhartiya & Shailendra Shriwastava, βARMOR: An Extensible Multi-Provider Secret Validation Framework for Automated Credential Verification in DevSecOps Pipelines,β International Journal of Advanced Research in Computer and Communication Engineering (IJARCCE), DOI: 10.17148/IJARCCE.2026.15920
