Logitech / vr_ink_sdk

Logitech VR Ink SDK repository
MIT License
18 stars 5 forks source link

Secret(s) found: 3 - [Product Security - Secret Scanning] #2

Closed nhamzi closed 1 year ago

nhamzi commented 1 year ago

This is automated issue created by Logitech Secret Scanner v1.0 - Nabil Hamzi

It seems that information looking like a secret (password, token, credentials, ...) has been identified in this github repository. We should avoid as much as possible to store secrets in Github code repository. Github has an 'encrypted secrets' feature for this. Please react on this thread with @nhamzi for any question.

Here are the findings, SecretLink contains the link to the sensitive value to be renewed, refreshed and deleted.

SecretLink=https://github.com/Logitech/vr_ink_sdk/blob/43f88b05a3664e00b52a045ba8b2d53ea53ecf8a/Assets/Toolkit/ProjectSettings/ProjectSettings.asset#L537-L538 SecretLink=https://github.com/Logitech/vr_ink_sdk/blob/43f88b05a3664e00b52a045ba8b2d53ea53ecf8a/Assets/UnitySampleProjects/UnitySample_SteamVR2.0/ProjectSettings/ProjectSettings.asset#L537-L538 SecretLink=https://github.com/Logitech/vr_ink_sdk/blob/7a4d09c24967c81efd0f8f748626238e5b9e22f5/code/unity_sample_app/ProjectSettings/ProjectSettings.asset#L581-L582

nhamzi commented 1 year ago

Checked with @mario-gutierrez, this is a non-issue