Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Use a token format with a prefix #1475

Open
nicwortel opened this issue Oct 30, 2024 · 0 comments
Open

Use a token format with a prefix #1475

nicwortel opened this issue Oct 30, 2024 · 0 comments
Labels
Milestone

Comments

@nicwortel
Copy link

Private Packagist uses a token format with a prefix and checksum to help with automated scanning for commited secrets in codebases.
For an example, see Trivy: Secret scanning and aquasecurity/trivy#7826.

Doing the same for Packagist.org would allow those secret scanners to scan for Packagist.org tokens as well.

@nicwortel nicwortel changed the title Use a well-defined token format Use a token format with a prefix Oct 30, 2024
@Seldaek Seldaek added this to the nice-to-have milestone Oct 30, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants