Skip to content

Security finding β€” possible DB connection string with credentials (details on request)Β #1

@Raffa-jarrl

Description

@Raffa-jarrl

Hi πŸ‘‹

Automated scan from Lictor flagged a pattern that looks like a database connection string with embedded credentials in your public source. I verified the pattern matches; I did not verify it's a live production DB.

  • What I saw: a postgres:///mysql:///mongodb://-style URI with non-placeholder credentials.
  • Why it might matter: if the DB is reachable from the internet and the password is real, anyone reading the repo has read/write access.
  • What to check: the file the scan flagged. Reply here (or email Raffa@Lictor-AI.com) and I'll send path + line + redacted excerpt. If it's a test/sandbox/already-rotated, just say so and I'll close out.

Either way β€” thank you for the work you do on this repo. πŸ™

β€” Raffa Β· Lictor (open-source, Apache 2.0)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions