CycodeLabs / CycodeLabs/cycode-aws-live-stream

[Security Alert] Exposed API key(s) detected: AWS Access Key

未關閉
#2 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
主要語言
Java
星號
5
分支
2
PR 合併指標
30 天內沒有已合併 PR

描述

Hi,

An automated responsible-disclosure scan found pattern(s) matching the following API key type(s) in this file:

**https://github.com/CycodeLabs/cycode-aws-live-stream/blob/65db6ff5bad956443d9a40279c570570960c018f/stream2-17-01-2023/secrets-container/main.go**

### Keys detected

- **AWS Access Key** → revoke at https://console.aws.amazon.com/iam

### Recommended actions

1. **Revoke each key immediately** using the links above
2. **Remove the key(s) from the file** and commit the change
3. **Purge from git history** — keys remain accessible in old commits even after deletion. Use [`git filter-repo`](https://github.com/newren/git-filter-repo) or [BFG Repo Cleaner](https://rtyley.github.io/bfg-repo-cleaner/)
4. **Rotate any dependent services** that used these credentials

> This is an automated alert. No keys were tested, validated, or used in any way. If this is a false positive, please close this issue.

---
*Sent by a responsible disclosure scanner to help protect accidentally exposed credentials.*

貢獻指南

這個儲存庫沒有索引到貢獻指南

研究方向

從 stream2-17-01-2023/secrets-container/main.go 開始,並立即在 IAM 中撤銷已暴露的 AWS 金鑰。刪除憑證,使用 git filter-repo 或 BFG Repo Cleaner 將其從 Git 歷史記錄中徹底清除,並輪替相依服務;完成的標準是金鑰已撤銷、不再存在於檔案和歷史記錄中,且相依憑證已完成輪替。

由索引模型根據 Issue 內容生成。

評估

技術堆疊
aws, go
領域
cloud, security
Issue 類型
缺陷
難度
4/5
預估耗時
3-5 天
活躍度
停滯
描述清晰度
描述清楚
新手友好度
35/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。