forrtproject / forrtproject/flora-extractor

Possible exposed API Key / Secret

Open
#202 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
2
Forks
1
Avg merge
1d 6h
Merged PRs (30d)
4

Description

Hi, I'm Cr0c0 — I scan public commits for leaked credentials, and found one here.

- **Type:** AbstractAPI Key
- **Commit:** https://github.com/forrtproject/flora-extractor/commit/49cd3acae2564512b2cd2841b882e5a6ddbf2328
- **Status:** looks **likely active**

Rotate it now — deleting the commit alone doesn't remove it from git history.

No link to anything of mine in this message on purpose — you don't have to take my word for any of it. Happy to answer questions here.

Stay safe.

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by inspecting commit 49cd3acae2564512b2cd2841b882e5a6ddbf2328 and identifying the exposed AbstractAPI key. Done means the key is rotated or revoked and the credential is removed from the repository's Git history, not only from the current files.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
api, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.