Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

[Security Alert] Exposed API key(s) detected: AWS Access Key

オープン
#2 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
35/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
停滞
技術スタック
aws, go
領域
cloud, security

調査の方向性

stream2-17-01-2023/secrets-container/main.go から始め、公開された AWS キーを IAM ですぐに無効化します。認証情報を削除し、git filter-repo または BFG Repo Cleaner を使って Git 履歴から完全に除去し、依存するサービスの認証情報をローテーションします;完了とは、キーが無効化され、ファイルと履歴の両方からなくなり、依存する認証情報がローテーション済みであることを意味します。

索引モデルが issue の本文から書いたものです。

説明

Hi,

An automated responsible-disclosure scan found pattern(s) matching the following API key type(s) in this file:

https://github.com/CycodeLabs/cycode-aws-live-stream/blob/65db6ff5bad956443d9a40279c570570960c018f/stream2-17-01-2023/secrets-container/main.go

Keys detected
Recommended actions
  1. Revoke each key immediately using the links above
  2. Remove the key(s) from the file and commit the change
  3. Purge from git history — keys remain accessible in old commits even after deletion. Use git filter-repo or BFG Repo Cleaner
  4. Rotate any dependent services that used these credentials

This is an automated alert. No keys were tested, validated, or used in any way. If this is a false positive, please close this issue.


Sent by a responsible disclosure scanner to help protect accidentally exposed credentials.

主要言語
Java
スター
5
フォーク
2
PR マージ指標
30日以内にマージされた PR はありません

環境構築

このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

似ている issue

Java の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。