Conversation
|
Hi, I’m Jit, a friendly security platform designed to help developers build secure applications from day zero with an MVS (Minimal viable security) mindset. In case there are security findings, they will be communicated to you as a comment inside the PR. Hope you’ll enjoy using Jit. Questions? Comments? Want to learn more? Get in touch with us. |
| MAILGUN_API = 'key-LPxoYCANGEFkAMHBur4jTjbZ69ngpdbI' | ||
|
|
||
| GITHUB_PAT_ONE = 'ghp_00a00aDDAg111xaAA7nAA0AalMspJB0tNaaa' | ||
| GITHUB_PAT_TWO = 'ghp_99g00bXXGj528xxAA4kQG2CxlMspJB0tNxaz' |
There was a problem hiding this comment.
Security control: Secret Detection
Type: Github-Pat
Description: GitHub Personal Access Token
Severity: HIGH
Jit Bot commands and options (e.g., ignore issue)
You can trigger Jit actions by commenting on this PR review:
#jit_ignore_fpIgnore and mark this specific single instance of finding as “False Positive”#jit_ignore_acceptIgnore and mark this specific single instance of finding as “Accept Risk”#jit_undo_ignoreUndo ignore command
|
|
||
| STRIPE = 'pk_live_abcdefghijklmnopqrstuvwxyz0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ' | ||
|
|
||
| SLACK = 'xapp-1-A01C259PH2A-1440755929120-7d5241948a2cc1b464add85df8a8e75f9040ae2869f6599926ed0b9dcafdb32b' |
There was a problem hiding this comment.
Security control: Secret Detection
Type: Slack-App-Token
Description: Slack App-level token
Severity: HIGH
Jit Bot commands and options (e.g., ignore issue)
You can trigger Jit actions by commenting on this PR review:
#jit_ignore_fpIgnore and mark this specific single instance of finding as “False Positive”#jit_ignore_acceptIgnore and mark this specific single instance of finding as “Accept Risk”#jit_undo_ignoreUndo ignore command
|
|
||
| TWILIO_API = 'SK5d1d319A6Acf7EC9BDeDb8CCe4D76BA8' | ||
|
|
||
| MAILGUN_API = 'key-LPxoYCANGEFkAMHBur4jTjbZ69ngpdbI' |
There was a problem hiding this comment.
Security control: Secret Detection
Type: Generic-Api-Key
Description: Generic API Key
Severity: HIGH
Jit Bot commands and options (e.g., ignore issue)
You can trigger Jit actions by commenting on this PR review:
#jit_ignore_fpIgnore and mark this specific single instance of finding as “False Positive”#jit_ignore_acceptIgnore and mark this specific single instance of finding as “Accept Risk”#jit_undo_ignoreUndo ignore command
| jwt_secret: YourJWTSecretKeyHere | ||
| GOOGLE_API = 'AIzaSyBUPHAjZl3n8Eza66ka6B78iVyPteC5MgM' | ||
|
|
||
| STRIPE = 'pk_live_abcdefghijklmnopqrstuvwxyz0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ' |
There was a problem hiding this comment.
Security control: Secret Detection
Type: Stripe-Access-Token
Description: Stripe Access Token
Severity: HIGH
Jit Bot commands and options (e.g., ignore issue)
You can trigger Jit actions by commenting on this PR review:
#jit_ignore_fpIgnore and mark this specific single instance of finding as “False Positive”#jit_ignore_acceptIgnore and mark this specific single instance of finding as “Accept Risk”#jit_undo_ignoreUndo ignore command
|
|
||
| MAILGUN_API = 'key-LPxoYCANGEFkAMHBur4jTjbZ69ngpdbI' | ||
|
|
||
| GITHUB_PAT_ONE = 'ghp_00a00aDDAg111xaAA7nAA0AalMspJB0tNaaa' |
There was a problem hiding this comment.
Security control: Secret Detection
Type: Github-Pat
Description: GitHub Personal Access Token
Severity: HIGH
Jit Bot commands and options (e.g., ignore issue)
You can trigger Jit actions by commenting on this PR review:
#jit_ignore_fpIgnore and mark this specific single instance of finding as “False Positive”#jit_ignore_acceptIgnore and mark this specific single instance of finding as “Accept Risk”#jit_undo_ignoreUndo ignore command
| mysql_password: MySQLPassword123 | ||
| postgres_password: myPostgresPassw0rd | ||
| jwt_secret: YourJWTSecretKeyHere | ||
| GOOGLE_API = 'AIzaSyBUPHAjZl3n8Eza66ka6B78iVyPteC5MgM' |
There was a problem hiding this comment.
Security control: Secret Detection
Type: Gcp-Api-Key
Description: GCP API key
Severity: HIGH
Jit Bot commands and options (e.g., ignore issue)
You can trigger Jit actions by commenting on this PR review:
#jit_ignore_fpIgnore and mark this specific single instance of finding as “False Positive”#jit_ignore_acceptIgnore and mark this specific single instance of finding as “Accept Risk”#jit_undo_ignoreUndo ignore command
| SLACK_BOT = 'xoxb-730191371696-1413868247813-IG7Z6nYevC2hdviE3aJhb5kY' | ||
|
|
||
| AWS_KEY_ONE = 'AKIAIWSXFHRM7F6Z3NWQ' | ||
| AWS_KEY_TWO = 'AKIASLEPEFMTEF3JEWSP' |
There was a problem hiding this comment.
Security control: Secret Detection
Type: Aws-Access-Token
Description: AWS
Severity: HIGH
Jit Bot commands and options (e.g., ignore issue)
You can trigger Jit actions by commenting on this PR review:
#jit_ignore_fpIgnore and mark this specific single instance of finding as “False Positive”#jit_ignore_acceptIgnore and mark this specific single instance of finding as “Accept Risk”#jit_undo_ignoreUndo ignore command
| SLACK = 'xapp-1-A01C259PH2A-1440755929120-7d5241948a2cc1b464add85df8a8e75f9040ae2869f6599926ed0b9dcafdb32b' | ||
| SLACK_BOT = 'xoxb-730191371696-1413868247813-IG7Z6nYevC2hdviE3aJhb5kY' | ||
|
|
||
| AWS_KEY_ONE = 'AKIAIWSXFHRM7F6Z3NWQ' |
There was a problem hiding this comment.
Security control: Secret Detection
Type: Aws-Access-Token
Description: AWS
Severity: HIGH
Jit Bot commands and options (e.g., ignore issue)
You can trigger Jit actions by commenting on this PR review:
#jit_ignore_fpIgnore and mark this specific single instance of finding as “False Positive”#jit_ignore_acceptIgnore and mark this specific single instance of finding as “Accept Risk”#jit_undo_ignoreUndo ignore command
| STRIPE = 'pk_live_abcdefghijklmnopqrstuvwxyz0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ' | ||
|
|
||
| SLACK = 'xapp-1-A01C259PH2A-1440755929120-7d5241948a2cc1b464add85df8a8e75f9040ae2869f6599926ed0b9dcafdb32b' | ||
| SLACK_BOT = 'xoxb-730191371696-1413868247813-IG7Z6nYevC2hdviE3aJhb5kY' |
There was a problem hiding this comment.
Security control: Secret Detection
Type: Slack-Bot-Token
Description: Slack Bot token
Severity: HIGH
Jit Bot commands and options (e.g., ignore issue)
You can trigger Jit actions by commenting on this PR review:
#jit_ignore_fpIgnore and mark this specific single instance of finding as “False Positive”#jit_ignore_acceptIgnore and mark this specific single instance of finding as “Accept Risk”#jit_undo_ignoreUndo ignore command
| AWS_KEY_ONE = 'AKIAIWSXFHRM7F6Z3NWQ' | ||
| AWS_KEY_TWO = 'AKIASLEPEFMTEF3JEWSP' | ||
|
|
||
| TWILIO_API = 'SK5d1d319A6Acf7EC9BDeDb8CCe4D76BA8' |
There was a problem hiding this comment.
Security control: Secret Detection
Type: Twilio-Api-Key
Description: Twilio API Key
Severity: HIGH
Jit Bot commands and options (e.g., ignore issue)
You can trigger Jit actions by commenting on this PR review:
#jit_ignore_fpIgnore and mark this specific single instance of finding as “False Positive”#jit_ignore_acceptIgnore and mark this specific single instance of finding as “Accept Risk”#jit_undo_ignoreUndo ignore command
Thank you for submitting a pull request to the WebGoat!