github / github/codeql

False positive: Env var is from config, not vault, and contains the name of another env var

Offen
#19,681 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
false-positive
Vorherrschende Sprache
CodeQL
Sterne
10.1k
Forks
2.1k
Ø Merge
2 T. 15 Std.
Gemergte PRs (30 T.)
141

Beschreibung

**Description of the false positive**

This flagged for outputting the value of an environment variable to logs. Generally, that could be a problem. In this case, the env var clearly contained the name of another env var to look in for the secret. Is there a way to not flag in this situation? For example, could we determine that this environment variable came from a k8s env var (where secrets are not allowed) as opposed to from vault?

**Code samples or links to source code**

https://github.com/github/blackbird/blob/d5fc30382331e6f5cd03c7f8695afadeeb631075/crates/config/src/embeddings.rs#L76-L79

**URL to the alert on GitHub code scanning (optional)**

https://github.com/github/blackbird/security/code-scanning/5068

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Start with the linked code in crates/config/src/embeddings.rs at lines 76-79 and inspect code-scanning alert 5068 to identify the CodeQL query and data-flow path producing the finding. Done means this configuration value is no longer reported as secret output while genuine environment-variable secret exposure remains detected.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
rust
Bereich
security
Issue-Typ
Bug
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Veraltet
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
35/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.