API keys, passwords or tokens committed into the repo.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
pkg/tlsclientconfig/testdata/full/client-cert-2.key:1
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
pkg/tlsclientconfig/testdata/full/client-cert-1.key:1
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
docker/daemon/testdata/certs/key.pem:1
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
oci/layout/fixtures/accepted_certs/cert.key:1
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
oci/layout/fixtures/rejected_certs/cert.key:1
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
docker/daemon/testdata/certs/key.pem:1
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
oci/layout/fixtures/accepted_certs/cert.key:1
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
oci/layout/fixtures/rejected_certs/cert.key:1
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
docker/daemon/testdata/certs/key.pem:1
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
oci/layout/fixtures/accepted_certs/cert.key:1
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
oci/layout/fixtures/rejected_certs/cert.key:1
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
docker/daemon/testdata/certs/key.pem:1
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
oci/layout/fixtures/accepted_certs/cert.key:1
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
oci/layout/fixtures/rejected_certs/cert.key:1
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
copy/sign_test.go:22
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
signature/fixtures/policy.json:56
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
signature/fixtures/policy.json:64
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
signature/fixtures_info_test.go:11
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
signature/policy_types.go:94
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
signature/policy_types.go:97
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
copy/sign_test.go:22
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
signature/fixtures/policy.json:56
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
signature/fixtures/policy.json:64
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
signature/fixtures_info_test.go:11
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
-
Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
signature/policy_types.go:94
A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.