API keys, passwords or tokens committed into the repo.
-
Serious jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.
incubator/distribution/ci/test-values.yaml:12
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
incubator/webpagetest-server/README.md:146
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious curl-auth-user Discovered a potential basic authorization token provided in a curl command, which could compromise the curl accessed resource.
stable/bitcoind/templates/NOTES.txt:12
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious jwt Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.
stable/distribution/ci/test-values.yaml:12
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
stable/concourse/values.yaml:1795
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
stable/concourse/values.yaml:1830
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
stable/concourse/values.yaml:1862
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious curl-auth-header Discovered a potential authorization token provided in a curl command header, which could compromise the curl accessed resource.
stable/falco/values.yaml:231
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
stable/graylog/README.md:201
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
stable/hlf-ord/tests/fixtures/crypto/orderer/4ca789b7ba945262b58f873358ef32947fe450d949084a887995a7aa89a95ee1_sk:1
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
stable/hlf-peer/tests/fixtures/crypto/admin/478bb28c12190a41a8eb361c6815cf91a0d0ec291f0977f562661a67b1c250dd_sk:1
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
stable/hlf-peer/tests/fixtures/crypto/peer/22de23eeb2b0259b6b739a6954408780beb9e614858c879c75df2e6d04325bf4_sk:1
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious slack-webhook-url Discovered a Slack Webhook, which could lead to unauthorized message posting and data leakage in Slack channels.
stable/kube-slack/values.yaml:4
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
stable/kiam/ci/test-values.yaml:6
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
stable/kiam/ci/test-values.yaml:15
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
stable/mission-control/ci/test-values.yaml:15
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
stable/openebs/templates/validationwebhook.yaml:56
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
stable/wordpress/README.md:320
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
stable/traefik/values.yaml:136
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
incubator/burrow/values.yaml:78
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
stable/anchore-engine/templates/engine_configmap.yaml:82
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
stable/artifactory/README.md:79
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
stable/burrow/templates/test-secret.yaml:21
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
stable/burrow/templates/test-secret.yaml:22
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
stable/burrow/templates/test-secret.yaml:23
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.