Skip to content

New vulnerability#5

Open
claire-villard-sonarsource wants to merge 3 commits intomainfrom
new-vulnerability
Open

New vulnerability#5
claire-villard-sonarsource wants to merge 3 commits intomainfrom
new-vulnerability

Conversation

@claire-villard-sonarsource
Copy link
Copy Markdown
Owner

No description provided.

Comment thread src/Config.js
@@ -0,0 +1,12 @@
import firebase from 'firebase'

const aws_access_key_id = "ASIALKSJGJSHBGSL135H"

Check failure

Code scanning / SonarCloudsquad-1

Amazon Web Services credentials should not be disclosed

<!--SONAR_ISSUE_KEY:AYhYxCuU6EhLaUgqJ0NL-->Make sure this AWS Access Key ID is not disclosed. <p>See more on <a href="https://squad-1-core.sc-dev.io/project/issues?id=claire-villard-sonarsource_test-vue-issue&issues=AYhYxCuU6EhLaUgqJ0NL&open=AYhYxCuU6EhLaUgqJ0NL&pullRequest=5">SonarCloud</a></p>
Comment thread src/Config.js
@@ -0,0 +1,12 @@
import firebase from 'firebase'

const aws_access_key_id = "ASIALKSJGJSHBGSL135H"

Check failure

Code scanning / SonarCloudsquad-2

Amazon Web Services credentials should not be disclosed

<!--SONAR_ISSUE_KEY:AYhYxEmeYus4ag5Kh3Q5-->Make sure this AWS Access Key ID is not disclosed. <p>See more on <a href="https://squad-2-core.sc-dev.io/project/issues?id=claire-villard-sonarsource_test-vue-issue&issues=AYhYxEmeYus4ag5Kh3Q5&open=AYhYxEmeYus4ag5Kh3Q5&pullRequest=5">SonarCloud</a></p>
Comment thread src/Config.js Fixed
Comment thread src/Config.js
@@ -0,0 +1,12 @@
import firebase from 'firebase'

const aws_access_key_id = "ASIALKSJGJSHBGSL135H"

Check failure

Code scanning / SonarCloudsquad-3

Amazon Web Services credentials should not be disclosed

<!--SONAR_ISSUE_KEY:AYhYxFT7lg2aQqTzhPlJ-->Make sure this AWS Access Key ID is not disclosed. <p>See more on <a href="https://squad-3-core.sc-dev.io/project/issues?id=claire-villard-sonarsource_test-vue-issue&issues=AYhYxFT7lg2aQqTzhPlJ&open=AYhYxFT7lg2aQqTzhPlJ&pullRequest=5">SonarCloud</a></p>
Comment thread src/Config.js Fixed
Comment thread src/Config.js Fixed
Comment thread src/Config.js
@@ -0,0 +1,12 @@
import firebase from 'firebase'

const aws_access_key_id = "ASIALKSJGJSHBGSL135H"

Check failure

Code scanning / SonarCloudsquad-5

Amazon Web Services credentials should not be disclosed

<!--SONAR_ISSUE_KEY:AYkwOKamn8Vp1FcXsEZJ-->Make sure this AWS Access Key ID is not disclosed. <p>See more on <a href="https://squad-5-core.sc-dev.io/project/issues?id=claire-villard-sonarsource_test-vue-issue&issues=AYkwOKamn8Vp1FcXsEZJ&open=AYkwOKamn8Vp1FcXsEZJ&pullRequest=5">SonarCloud</a></p>
Comment thread src/Config.js
@@ -0,0 +1,12 @@
import firebase from 'firebase'

const aws_access_key_id = "ASIALKSJGJSHBGSL135H"

Check failure

Code scanning / SonarCloudStaging

Amazon Web Services credentials should not be disclosed

<!--SONAR_ISSUE_KEY:AYn95jd0xLPUlgkTLEm6-->Make sure this AWS Access Key ID gets revoked, changed, and removed from the code. <p>See more on <a href="https://sc-staging.io/project/issues?id=claire-villard-sonarsource_test-vue-issue&issues=AYn95jd0xLPUlgkTLEm6&open=AYn95jd0xLPUlgkTLEm6&pullRequest=5">SonarCloud</a></p>
Comment thread src/Config.js
@@ -0,0 +1,12 @@
import firebase from 'firebase'

const aws_access_key_id = "ASIALKSJGJSHBGSL135H"

Check failure

Code scanning / SonarCloudDev

Amazon Web Services credentials should not be disclosed

<!--SONAR_ISSUE_KEY:AYqE3vuxNUIodHWTmwJW-->Make sure this AWS Access Key ID gets revoked, changed, and removed from the code. <p>See more on <a href="https://dev.sc-dev.io/project/issues?id=claire-villard-sonarsource_test-vue-issue&issues=AYqE3vuxNUIodHWTmwJW&open=AYqE3vuxNUIodHWTmwJW&pullRequest=5">SonarCloud</a></p>
Comment thread src/Config.js Fixed
Comment thread src/Config.js Fixed
@ghost
Copy link
Copy Markdown

ghost commented Oct 13, 2023

SonarCloud Quality Gate failed.    Quality Gate failed

Bug A 0 Bugs
Vulnerability E 1 Vulnerability
Security Hotspot A 0 Security Hotspots
Code Smell A 1 Code Smell

No Coverage information No Coverage information
0.0% 0.0% Duplication

idea Catch issues before they fail your Quality Gate with our IDE extension sonarlint SonarLint

Comment thread src/Config.js Fixed
@ghost
Copy link
Copy Markdown

ghost commented Oct 13, 2023

SonarCloud Quality Gate failed.    Quality Gate failed

Bug A 0 Bugs
Vulnerability E 1 Vulnerability
Security Hotspot A 0 Security Hotspots
Code Smell A 1 Code Smell

No Coverage information No Coverage information
0.0% 0.0% Duplication

idea Catch issues before they fail your Quality Gate with our IDE extension sonarlint SonarLint

Comment thread src/Config.js
@@ -0,0 +1,12 @@
import firebase from 'firebase'

const aws_access_key_id = "ASIALKSJGJSHBGSL135H"

Check failure

Code scanning / SonarCloudsquad-4

Amazon Web Services credentials should not be disclosed

<!--SONAR_ISSUE_KEY:AYsobsZ0DTP1HF8QknEN-->Make sure the access granted with this AWS access key ID is restricted <p>See more on <a href="https://squad-4-core.sc-dev.io/project/issues?id=claire-villard-sonarsource_test-vue-issue&issues=AYsobsZ0DTP1HF8QknEN&open=AYsobsZ0DTP1HF8QknEN&pullRequest=5">SonarCloud</a></p>
Repository owner deleted a comment Sep 29, 2025
Repository owner deleted a comment Sep 29, 2025
Repository owner deleted a comment from sonarqube-cloud-dev Bot Sep 29, 2025
Repository owner deleted a comment Sep 29, 2025
Repository owner deleted a comment Sep 29, 2025
Repository owner deleted a comment from sonarqube-cloud-staging Bot Sep 29, 2025
Repository owner deleted a comment Sep 29, 2025
@sonarclouddev5
Copy link
Copy Markdown

Repository owner deleted a comment from sonarqube-cloud-staging Bot Sep 29, 2025
Repository owner deleted a comment from sonarqube-cloud-dev Bot Sep 29, 2025
Repository owner deleted a comment from sonarqubecloud Bot Sep 29, 2025
@sonarqube-cloud-dev19
Copy link
Copy Markdown

🤖 Pull Request summary

SECURITY CRITICAL - Configuration file with exposed credentials added.

• New Config.js file created with Firebase configuration object
• AWS access key ID hardcoded in plaintext variable
• Firebase API keys and project settings exposed in source code

⚠️ IMMEDIATE ATTENTION REQUIRED: This PR contains hardcoded secrets that must be moved to environment variables or secure config management before merging. All exposed credentials should be rotated.

💬 Please send your feedback

Quality Gate Passed Quality Gate passed

Issues
1 New issue
0 Accepted issues

Measures
0 Security Hotspots
0.0% Coverage on New Code
0.0% Duplication on New Code

See analysis details on SonarQube Cloud

@sonarqube-cloud-dev17
Copy link
Copy Markdown

@sonarclouddev5
Copy link
Copy Markdown

@sonarqube-cloud-dev19
Copy link
Copy Markdown

@sonarclouddev7
Copy link
Copy Markdown

sonarclouddev7 Bot commented Nov 3, 2025

1 similar comment
@sonarclouddev7
Copy link
Copy Markdown

sonarclouddev7 Bot commented Nov 7, 2025

@sonarqube-cloud-dev17
Copy link
Copy Markdown

@sonarqube-cloud-dev17
Copy link
Copy Markdown

Review in SonarQube
See all code changes, issues, and quality metrics in one place.

Quality Gate Passed Quality Gate passed

Issues
1 New issue
0 Accepted issues

Measures
0 Security Hotspots
0.0% Coverage on New Code
0.0% Duplication on New Code

See analysis details on SonarQube Cloud

@sonarclouddev10
Copy link
Copy Markdown

Review in SonarQube
See all code changes, issues, and quality metrics in one place.

Quality Gate Passed Quality Gate passed

Issues
1 New issue
0 Accepted issues

Measures
0 Security Hotspots
0.0% Coverage on New Code
0.0% Duplication on New Code

See analysis details on SonarQube Cloud

@sonarqube-cloud-dev11
Copy link
Copy Markdown

Review in SonarQube
See all code changes, issues, and quality metrics in one place.

Quality Gate Passed Quality Gate passed

Issues
1 New issue
0 Accepted issues

Measures
0 Security Hotspots
0.0% Coverage on New Code
0.0% Duplication on New Code

See analysis details on SonarQube Cloud

@sonarclouddev13
Copy link
Copy Markdown

Review in SonarQube
See all code changes, issues, and quality metrics in one place.

Quality Gate Passed Quality Gate passed

Issues
1 New issue
0 Accepted issues

Measures
0 Security Hotspots
0.0% Coverage on New Code
0.0% Duplication on New Code

See analysis details on SonarQube Cloud

@sonarclouddev9
Copy link
Copy Markdown

sonarclouddev9 Bot commented Feb 4, 2026

Review in SonarQube
See all code changes, issues, and quality metrics in one place.

Quality Gate Passed Quality Gate passed

Issues
1 New issue
0 Accepted issues

Measures
0 Security Hotspots
0.0% Coverage on New Code
0.0% Duplication on New Code

See analysis details on SonarQube Cloud

@sonarclouddev14
Copy link
Copy Markdown

Review in SonarQube
See all code changes, issues, and quality metrics in one place.

Quality Gate Passed Quality Gate passed

Issues
1 New issue
0 Accepted issues

Measures
0 Security Hotspots
0.0% Coverage on New Code
0.0% Duplication on New Code

See analysis details on SonarQube Cloud

@sonarqube-cloud-dev19
Copy link
Copy Markdown

Review in SonarQube
See all code changes, issues, and quality metrics in one place.

Quality Gate Passed Quality Gate passed

Issues
1 New issue
0 Accepted issues

Measures
0 Security Hotspots
0.0% Coverage on New Code
0.0% Duplication on New Code

See analysis details on SonarQube Cloud

@sonarqube-cloud-dev17
Copy link
Copy Markdown

Review in SonarQube
See all code changes, issues, and quality metrics in one place.

Quality Gate Passed Quality Gate passed

Issues
1 New issue
0 Accepted issues

Measures
0 Security Hotspots
0.0% Coverage on New Code
0.0% Duplication on New Code

See analysis details on SonarQube Cloud

@sonarclouddev4
Copy link
Copy Markdown

sonarclouddev4 Bot commented Feb 4, 2026

Review in SonarQube
See all code changes, issues, and quality metrics in one place.

❌ The last analysis has failed.

See analysis details on SonarQube Cloud

@sonarclouddev5
Copy link
Copy Markdown

Review in SonarQube
See all code changes, issues, and quality metrics in one place.

Quality Gate Passed Quality Gate passed

Issues
1 New issue
0 Accepted issues

Measures
0 Security Hotspots
0.0% Coverage on New Code
0.0% Duplication on New Code

See analysis details on SonarQube Cloud

@sonarqubecloud
Copy link
Copy Markdown

@sonarqube-cloud-dev18
Copy link
Copy Markdown

@sonarqube-cloud-dev17
Copy link
Copy Markdown

Review in SonarQube
See all code changes, issues, and quality metrics in one place.

Quality Gate Passed Quality Gate passed

Issues
1 New issue
0 Accepted issues

Measures
0 Security Hotspots
0.0% Coverage on New Code
0.0% Duplication on New Code

See analysis details on SonarQube Cloud

@sonarclouddev12
Copy link
Copy Markdown

@sonarqube-cloud-staging
Copy link
Copy Markdown

@sonarclouddev12
Copy link
Copy Markdown

@sonarqubecloud
Copy link
Copy Markdown

1 similar comment
@sonarqubecloud
Copy link
Copy Markdown

@sonarclouddev5
Copy link
Copy Markdown

sonarclouddev5 Bot commented Mar 3, 2026

1 similar comment
@sonarclouddev5
Copy link
Copy Markdown

sonarclouddev5 Bot commented Mar 3, 2026

@sonarclouddev6
Copy link
Copy Markdown

sonarclouddev6 Bot commented Mar 4, 2026

@sonarqube-cloud-staging
Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants