Closed darkarnium closed 2 years ago
STACS has found a potential static token or credential at line 1 of tests/fixtures/ci/credential.txt
due to potential AWS access key found.
If this credential is valid it should be immediately revoked, and the cause of this credential making it into this file investigated.
If this finding is against a 'fake' credential, such as in a test fixture, this finding can be suppressed using an ignore list in the root of this repository. A basic ignore list entry can be found below which may be suitable, otherwise, please refer to the STACS documentation
[V:0.4.4, R:CredentialCloudAWSAccessKey, F:ddf2c31a0f0978a5f4f3dc21c84d0f2dfd4dc135]
STACS has found a potential static token or credential at line 2 of tests/fixtures/ci/credential.txt
due to potential AWS Secret key found.
If this credential is valid it should be immediately revoked, and the cause of this credential making it into this file investigated.
If this finding is against a 'fake' credential, such as in a test fixture, this finding can be suppressed using an ignore list in the root of this repository. A basic ignore list entry can be found below which may be suitable, otherwise, please refer to the STACS documentation
[V:0.4.4, R:CredentialCloudAWSSecretKey, F:9814f36e9fb74217d415b902639de028644e56ad]
Overview
PLEASE NOTE: There is a potentially breaking change as part of this update, as the Stripe rule has been relocated under
SaaS
. This modifies its reference to now beCredentialSaaSStripeAPI
. Any previously suppressed findings for this rule will need to be updated to reflect this new identifier.🛠️ New Features
xoxp-...
)xoxb-...
)authToken
password
3
/65537
, and modulous sizes64
/128
/256
/512
/1024
.🍩 Improvements
🐛 Bug Fixes