CycodeLabs / CycodeLabs/cycode-aws-live-stream
[Security Alert] Exposed API key(s) detected: AWS Access Key
- 主要語言
- Java
- 星號
- 5
- 分支
- 2
- PR 合併指標
- 30 天內沒有已合併 PR
描述
Hi,
An automated responsible-disclosure scan found pattern(s) matching the following API key type(s) in this file:
**https://github.com/CycodeLabs/cycode-aws-live-stream/blob/65db6ff5bad956443d9a40279c570570960c018f/stream2-17-01-2023/secrets-container/main.go**
### Keys detected
- **AWS Access Key** → revoke at https://console.aws.amazon.com/iam
### Recommended actions
1. **Revoke each key immediately** using the links above
2. **Remove the key(s) from the file** and commit the change
3. **Purge from git history** — keys remain accessible in old commits even after deletion. Use [`git filter-repo`](https://github.com/newren/git-filter-repo) or [BFG Repo Cleaner](https://rtyley.github.io/bfg-repo-cleaner/)
4. **Rotate any dependent services** that used these credentials
> This is an automated alert. No keys were tested, validated, or used in any way. If this is a false positive, please close this issue.
---
*Sent by a responsible disclosure scanner to help protect accidentally exposed credentials.*
貢獻指南
這個儲存庫沒有索引到貢獻指南
研究方向
從 stream2-17-01-2023/secrets-container/main.go 開始,並立即在 IAM 中撤銷已暴露的 AWS 金鑰。刪除憑證,使用 git filter-repo 或 BFG Repo Cleaner 將其從 Git 歷史記錄中徹底清除,並輪替相依服務;完成的標準是金鑰已撤銷、不再存在於檔案和歷史記錄中,且相依憑證已完成輪替。
由索引模型根據 Issue 內容生成。
評估
- 技術堆疊
- aws, go
- 領域
- cloud, security
- Issue 類型
- 缺陷
- 難度
- 4/5
- 預估耗時
- 3-5 天
- 活躍度
- 停滯
- 描述清晰度
- 描述清楚
- 新手友好度
- 35/100