We’ve been using SOPS as our secrets management solution for years. I really like it and the convenience of having secrets stored in git is hard to beat. Lately we have begun to review our DevSecOps practices and I can’t really find a solid answer as to how secure SOPS is. I’m hoping an expert could chime in.
I’ve read the sops docs and a handful of articles that talk about implementing SOPS, but nothing explicitly discusses how secure it is.