Skip to content

Possible exposed API Key / Secret #1

Description

@Leakwatch-Alert-Bot

Important

Moderate — C (65/100)
JWT exposed, validity undetermined.

  • Published in the public commit stream, which harvesters also read.
    Based on public commits only — the full git history may hold more.

Hi, I'm Cr0c0 : I run independant automated scans over public github repos looking for leaked credentials, and I found this.

I found JWT in the following commit : 7e01008. It looks likely active.

Im sorry for you but once a key is exposed in a public commit, it's compromised, even deleting it after won't help since it stays in git history. You need to rotate it now to be safe.

I did a short report of this leak if you wants to know how to delete it : https://leakwatch.net/r/kV3IZyrnBwNYV9-n (you don't need to login to see it).

Stay safe.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions