github / github/codeql

False positive: Env var is from config, not vault, and contains the name of another env var

未關閉
#19,681 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
false-positive
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

**Description of the false positive**

This flagged for outputting the value of an environment variable to logs. Generally, that could be a problem. In this case, the env var clearly contained the name of another env var to look in for the secret. Is there a way to not flag in this situation? For example, could we determine that this environment variable came from a k8s env var (where secrets are not allowed) as opposed to from vault?

**Code samples or links to source code**

https://github.com/github/blackbird/blob/d5fc30382331e6f5cd03c7f8695afadeeb631075/crates/config/src/embeddings.rs#L76-L79

**URL to the alert on GitHub code scanning (optional)**

https://github.com/github/blackbird/security/code-scanning/5068

貢獻指南

開啟貢獻指南

研究方向

Start with the linked code in crates/config/src/embeddings.rs at lines 76-79 and inspect code-scanning alert 5068 to identify the CodeQL query and data-flow path producing the finding. Done means this configuration value is no longer reported as secret output while genuine environment-variable secret exposure remains detected.

由索引模型根據 Issue 內容生成。

評估

技術堆疊
rust
領域
security
Issue 類型
缺陷
難度
4/5
預估耗時
3-5 天
活躍度
停滯
描述清晰度
基本清楚
新手友好度
35/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。