Hi, I'm Cr0c0 — I run automated scans over public commits looking for leaked credentials, and this repo showed up.
- Type: Docker Registry Auth (base64)
- Commit: 3699c56
- Status: looks likely active
This is a good-faith heads-up, nothing is expected of you. Once a key hits a public commit it's compromised, even if you delete it after (it stays in the git history). What matters: rotate it now, deleting the commit isn't enough.
I put together a short report for this repo — the exact line, every other credential I found in its history, and the revocation steps for this specific provider:
https://leakwatch.net/r/jG9eXnPtcc52ZFKx
No signup, nothing to install. Happy to walk through it right here in this thread instead if you prefer.
Stay safe.
Hi, I'm Cr0c0 — I run automated scans over public commits looking for leaked credentials, and this repo showed up.
This is a good-faith heads-up, nothing is expected of you. Once a key hits a public commit it's compromised, even if you delete it after (it stays in the git history). What matters: rotate it now, deleting the commit isn't enough.
I put together a short report for this repo — the exact line, every other credential I found in its history, and the revocation steps for this specific provider:
https://leakwatch.net/r/jG9eXnPtcc52ZFKx
No signup, nothing to install. Happy to walk through it right here in this thread instead if you prefer.
Stay safe.