Skip to content

fix: remove hardcoded secret in checkDASHardCodedValues.js (CWE-798) - #150

Closed
anupamme wants to merge 1 commit into
auth0:mainfrom
anupamme:fix-repo-auth0-checkmate-cwe-798-hardcoded-db-credentials-example
Closed

anupamme wants to merge 1 commit into
auth0:mainfrom
anupamme:fix-repo-auth0-checkmate-cwe-798-hardcoded-db-credentials-example

Conversation

@anupamme

Copy link
Copy Markdown

Hardcoded database credentials (user: 'me', password: 'secret') are present in example code within checkDASHardCodedValues.js. These credentials appear in a multi-line comment containing sample Auth0 database connection configuration that is used as test data for the hardcoded value detection check. While these are not production credentials, their presence violates security best practices and could lead to accidental exposure of real credentials if developers copy this pattern. The affected code is analyzer/lib/databases/checkDASHardCodedValues.js:41. This change is the fix I would apply.

Reference: CWE-798

What changed

  • analyzer/lib/databases/checkDASHardCodedValues.js

Verification

No automated check could be run against this repository, so this change is unverified beyond review. Please treat it as a suggestion.


Automated security fix by OrbisAI Security

Automated security fix generated by OrbisAI Security
@anupamme
anupamme requested a review from a team as a code owner September 28, 2026 00:28
@yangwang-okta

Copy link
Copy Markdown
Contributor

this defects the purpose of this check and the sample response associated with it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants