[high] semgrep: Generic Secret detected #37

Open
opened 2026-03-11 15:52:43 +00:00 by sharang · 0 comments
Owner

high Finding

Scanner: semgrep
Severity: high
Rule: generic.secrets.security.detected-generic-secret.detected-generic-secret

Description

Generic Secret detected

Location

File: /tmp/compliance-scanner/repos/certifai/docker-compose.yml (line 83)

Code

requires login

Remediation

Move all secrets to external secret management (e.g., Docker secrets, Kubernetes secrets, or environment variable files). Replace hardcoded values with references to external secrets. Example fix: 'JWT_SECRET: ${JWT_SECRET}' instead of 'JWT_SECRET: "767b962176666eab56e180e6f2d3fe95145dc6b978e37d4eb8d1da5421c5fb26"'


Fingerprint: 6b77c42afa89ae880d2f329a0e919b21ea3f5cb640d19604d4b4cecaf7812450
Generated by compliance-scanner

Labels: severity:high, scanner:semgrep, compliance-scanner

## high Finding **Scanner:** semgrep **Severity:** high **Rule:** generic.secrets.security.detected-generic-secret.detected-generic-secret ### Description Generic Secret detected ### Location **File:** `/tmp/compliance-scanner/repos/certifai/docker-compose.yml` (line 83) ### Code ``` requires login ``` ### Remediation Move all secrets to external secret management (e.g., Docker secrets, Kubernetes secrets, or environment variable files). Replace hardcoded values with references to external secrets. Example fix: 'JWT_SECRET: ${JWT_SECRET}' instead of 'JWT_SECRET: "767b962176666eab56e180e6f2d3fe95145dc6b978e37d4eb8d1da5421c5fb26"' --- *Fingerprint:* `6b77c42afa89ae880d2f329a0e919b21ea3f5cb640d19604d4b4cecaf7812450` *Generated by compliance-scanner* **Labels:** severity:high, scanner:semgrep, compliance-scanner
Sign in to join this conversation.
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sharang/certifai#37