Leaked API keys detected — 1 findings across 1 providers
- Dominant language
- PHP
- Stars
- 1
- Forks
- 1
- Avg merge
- 1d 10h
- Merged PRs (30d)
- 17
Description
## Possible API Key Exposure Detected
> **Heads up** — our automated scanner may have found exposed API keys in this repository.
> Please take a moment to review the findings below. If any of these are real credentials, we'd strongly recommend revoking and rotating them as soon as possible.
We're v1olet, an offensive security research team. This report was generated automatically as part of responsible disclosure — we haven't stored, used, or shared any of the potential keys found.
---
**1 potential finding(s)** were flagged across **1 provider(s)**.
> **Note:** This may be a false positive — leaked test keys, example placeholders, or already-rotated credentials can trigger our scanner. If that's the case here, feel free to close this issue.
### Findings
- **discord_webhook_url**: 1 finding(s)
### Detailed Findings
#### Discord Webhook URL
- **Partial Key:** `https:****`
- **File:** `.github/workflows/e2e-tests.yml`
- **Source:** code`
- **Confidence:** high
---
*This report was auto-generated by KeyHunter v9 by v1olet Security — please revoke and remove the keys from public view immediately if these are actual API keys.*
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by reviewing .github/workflows/e2e-tests.yml and inspect the reported Discord webhook URL in context. Verify whether it is a real credential or a test/example value, then confirm the finding is no longer exposed and that the workflow remains valid; ask the maintainers about rotation if needed.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions
- Domain
- ci-cd, security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Quiet
- Clarity
- Clearly specified
- Newbie friendliness
- 68/100