Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: Remove sensitive GitHub app keys and MongoDB configuration #1394

Merged
merged 1 commit into from
Dec 23, 2023

Conversation

MartinWitt
Copy link
Owner

No description provided.

Sensitive GitHub app keys and MongoDB database configuration were detected in the source code, which posed a security risk. Specifically, the development private key information for the GitHub application and the MongoDB database setting have been removed from the 'application.properties' file.
Copy link

gitguardian bot commented Dec 23, 2023

⚠️ GitGuardian has uncovered 1 secret following the scan of your pull request.

Please consider investigating the findings and remediating the incidents. Failure to do so may lead to compromising the associated services or software components.

🔎 Detected hardcoded secret in your pull request
GitGuardian id Secret Commit Filename
4393125 RSA Private Key cb09e5d github-bot/src/main/resources/application.properties View secret
🛠 Guidelines to remediate hardcoded secrets
  1. Understand the implications of revoking this secret by investigating where it is used in your code.
  2. Replace and store your secret safely. Learn here the best practices.
  3. Revoke and rotate this secret.
  4. If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.

To avoid such incidents in the future consider


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.

Our GitHub checks need improvements? Share your feedbacks!

@MartinWitt MartinWitt changed the title refactor/properties fix: Remove sensitive GitHub app keys and MongoDB configuration Dec 23, 2023
gitstream-cm[bot]
gitstream-cm bot previously approved these changes Dec 23, 2023
Copy link

gitstream-cm bot commented Dec 23, 2023

This PR has been approved because it is only a single line

gitstream-cm[bot]
gitstream-cm bot previously requested changes Dec 23, 2023
Copy link

@gitstream-cm gitstream-cm bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All PRs must be titled according to our semantic naming policy: <type>(<scope>): <short summary>

Type must be one of the following:

  • build
  • ci
  • chore
  • docs
  • feat
  • fix
  • refactor

Copy link

gitstream-cm bot commented Dec 23, 2023

This PR has been approved because it is only a single line

Copy link

gitstream-cm bot commented Dec 23, 2023

This PR is 0% new code.

@gitstream-cm gitstream-cm bot dismissed stale reviews from themself December 23, 2023 12:55

Review dismissed

Copy link
Contributor

Qodana Community for JVM

It seems all right 👌

No new problems were found according to the checks applied

💡 Qodana analysis was run in the pull request mode: only the changed files were checked

View the detailed Qodana report

To be able to view the detailed Qodana report, you can either:

  1. Register at Qodana Cloud and configure the action
  2. Use GitHub Code Scanning with Qodana
  3. Host Qodana report at GitHub Pages
  4. Inspect and use qodana.sarif.json (see the Qodana SARIF format for details)

To get *.log files or any other Qodana artifacts, run the action with upload-result option set to true,
so that the action will upload the files as the job artifacts:

      - name: 'Qodana Scan'
        uses: JetBrains/qodana-action@v2023.3.0
        with:
          upload-result: true
Contact Qodana team

Contact us at qodana-support@jetbrains.com

@MartinWitt MartinWitt merged commit 7ba7d8b into master Dec 23, 2023
11 of 13 checks passed
@MartinWitt MartinWitt deleted the refactor/properties branch December 23, 2023 13:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant