Skip to content

Secret leaked in proto/buf.yaml #2244

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
tolgaOzen opened this issue May 23, 2025 — with Aikido Issues · 0 comments
Closed

Secret leaked in proto/buf.yaml #2244

tolgaOzen opened this issue May 23, 2025 — with Aikido Issues · 0 comments
Labels

Comments

Copy link
Member

Find more live information in Aikido here: https://app.aikido.dev/queue?sidebarIssue=2485325&groupId=6798&sidebarIssueTask=580898&sidebarTab=tasks

Scope

This task includes issues in the following code repository:

  • permify: proto/buf.yaml

TLDR

We detected secret *****e517 in the git history of the repository. The secret was found in proto/buf.yaml.
View commit:

- buf.build/googleapis/googleapis:75b4300737fb4efca0831636be94e517

How to fix

If this API key is harmless, you can ignore this issue. If not, we would advise to move the secret out of the git repository by either injecting it via the environment or even better, by using a tool such as AWS Secrets Manager to inject the secrets at run-time. After that, it should be possible to invalidate the current secret and regenerate a new one.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant