API keys, passwords or tokens committed into the repo.
-
Serious jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.
incubator/distribution/ci/test-values.yaml:12
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
incubator/webpagetest-server/README.md:145
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious curl-auth-user Discovered a potential basic authorization token provided in a curl command, which could compromise the curl accessed resource.
stable/bitcoind/templates/NOTES.txt:12
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.
stable/distribution/ci/test-values.yaml:12
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
stable/concourse/values.yaml:658
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
stable/concourse/values.yaml:693
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
stable/concourse/values.yaml:725
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious curl-auth-header Discovered a potential authorization token provided in a curl command header, which could compromise the curl accessed resource.
stable/falco/values.yaml:169
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
stable/kiam/ci/test-values.yaml:6
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
stable/kiam/ci/test-values.yaml:15
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
stable/mission-control/ci/test-values.yaml:15
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
stable/wordpress/README.md:213
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
stable/traefik/values.yaml:58
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
incubator/burrow/values.yaml:78
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
stable/anchore-engine/templates/core_configmap.yaml:51
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
stable/burrow/ci/keys-values.yaml:6
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
stable/artifactory/README.md:79
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
stable/ethereum/ci/test-values.yaml:34
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
stable/ethereum/README.md:34
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
stable/ethereum/README.md:35
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
stable/falco/values.yaml:173
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
stable/mysqldump/README.md:9
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
stable/mysqldump/README.md:26
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
stable/rabbitmq-ha/values.yaml:9
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.