kubevela / kubevela/terraform-controller
Security report — possible Firebase service-account exposure (please contact privately)
- Dominant language
- Go
- Stars
- 163
- Forks
- 74
- PR merge metrics
- No merged PRs in 30d
Description
Hi —
I found what appears to be a Firebase / Google service-account JSON in your public repo. I'm not posting details here for responsible-disclosure reasons.
Please contact me at **raffa@lictorai.com** (or DM via GitHub) and I'll send the exact file path + line, plus the JWT payload decode confirming what the key grants access to.
**Time-sensitive**: service-account keys grant full GCP/Firebase project access until manually revoked. If real, the fix is two steps — rotate the key in Google Cloud Console, then git-history-rewrite to remove from repo history.
(Falling back to a public contact-request because your repo doesn't have GitHub's Private Vulnerability Reporting enabled for external reporters.)
**A note**: this came from an automated security scan I manually verified before reaching out. If we're wrong (it's a sample key, a test fixture, or an already-revoked credential), please reply and we'll close out. No blame intended.
— Raffa
Lictor AI · https://lictorai.com · github.com/Raffa-jarrl/Lictor-AI
Contributor guide
Research direction
Contact the reporter privately to obtain the exact file path, line, and JWT details, then verify whether the Firebase or Google service-account credential is real and active. Follow the repository's security process to revoke or rotate the key and remove the credential from Git history. Done means the credential is invalidated and the exposed material is no longer present in repository history.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- gcp, git, google-cloud
- Domain
- cloud, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100