Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[POC] Test gitguardian with fake credentials #801

Closed
wants to merge 5 commits into from

[pre-commit.ci] auto fixes from pre-commit.com hooks

8055938
Select commit
Loading
Failed to load commit list.
Closed

[POC] Test gitguardian with fake credentials #801

[pre-commit.ci] auto fixes from pre-commit.com hooks
8055938
Select commit
Loading
Failed to load commit list.
GitGuardian / GitGuardian Security Checks completed Oct 18, 2024 in 26s

3 secrets uncovered!

3 secrets were uncovered from the scan of 5 commits in your pull request. ❌

Please have a look to GitGuardian findings and remediate in order to secure your code.

Details

🔎 Detected hardcoded secrets in your pull request

  • Pull request #801: antonymilne-patch-1 👉 main
GitGuardian id GitGuardian status Secret Commit Filename
14157696 Triggered MongoDB Credentials a99773b README.md View secret
14200722 Triggered AWS Keys 942edc4 CODE_OF_CONDUCT.md View secret
14200722 Triggered AWS Keys 8055938 CODE_OF_CONDUCT.md View secret

🛠 Guidelines to remediate hardcoded secrets

  1. Understand the secret, review where it is currently used and what would be the impact of revoking/rotating the secret.
  2. Revoke or rotate the secret.
  3. Log in to GitGuardian and follow remediation guidance.

To avoid such incidents in the future, consider

If you have any questions or feedback, please reach out to us on #gitguardian slack channel.


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.