grafana / grafana/alerting

Leaked API keys detected — 1 findings across 1 providers

Open Beginner friendly
#651 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
89
Forks
74
Avg merge
2d 7h
Merged PRs (30d)
8

Description

## Possible API Key Exposure Detected

> **Heads up** — our automated scanner may have found exposed API keys in this repository.
> Please take a moment to review the findings below. If any of these are real credentials, we'd strongly recommend revoking and rotating them as soon as possible.

We're v1olet, an offensive security research team. This report was generated automatically as part of responsible disclosure — we haven't stored, used, or shared any of the potential keys found.

---

**1 potential finding(s)** were flagged across **1 provider(s)**.

> **Note:** This may be a false positive — leaked test keys, example placeholders, or already-rotated credentials can trigger our scanner. If that's the case here, feel free to close this issue.

### Findings

- **discord_webhook_url**: 1 finding(s)

### Detailed Findings

#### Discord Webhook URL

- **Partial Key:** `https:****`
- **File:** `receivers/discord/v0mimir1/discord_test.go`
- **Source:** code`
- **Confidence:** high

---

*This report was auto-generated by KeyHunter v9 by v1olet Security — please revoke and remove the keys from public view immediately if these are actual API keys.*

Contributor guide

Open the contributing guide

Research direction

Start by inspecting receivers/discord/v0mimir1/discord_test.go and the Discord webhook finding reported there. Determine whether the value is a real credential or a test/example value; if real, revoke or rotate it and remove it from public view. Verify the affected Go tests still pass and that no exposed credential remains.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
security, testing
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Quiet
Clarity
Clearly specified
Newbie friendliness
72/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.