From cbdf95b3aa8bb12d67f70f1c1ad21b8e6761519c Mon Sep 17 00:00:00 2001 From: John McCormack Date: Mon, 26 Apr 2021 16:11:41 +0100 Subject: [PATCH 1/3] generated .secrets.baseline --- .secrets.baseline | 262 ++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 262 insertions(+) create mode 100644 .secrets.baseline diff --git a/.secrets.baseline b/.secrets.baseline new file mode 100644 index 0000000..5eed283 --- /dev/null +++ b/.secrets.baseline @@ -0,0 +1,262 @@ +{ + "exclude": { + "files": "^.secrets.baseline$", + "lines": null + }, + "generated_at": "2021-04-26T15:08:22Z", + "plugins_used": [ + { + "name": "AWSKeyDetector" + }, + { + "name": "ArtifactoryDetector" + }, + { + "base64_limit": 4.5, + "name": "Base64HighEntropyString" + }, + { + "name": "BasicAuthDetector" + }, + { + "name": "BoxDetector" + }, + { + "name": "CloudantDetector" + }, + { + "name": "GheDetector" + }, + { + "hex_limit": 3, + "name": "HexHighEntropyString" + }, + { + "name": "IbmCloudIamDetector" + }, + { + "name": "IbmCosHmacDetector" + }, + { + "name": "JwtTokenDetector" + }, + { + "keyword_exclude": null, + "name": "KeywordDetector" + }, + { + "name": "MailchimpDetector" + }, + { + "name": "PrivateKeyDetector" + }, + { + "name": "SlackDetector" + }, + { + "name": "SoftlayerDetector" + }, + { + "name": "StripeDetector" + }, + { + "name": "TwilioKeyDetector" + } + ], + "results": { + "IBMCloudAppID.xcodeproj/xcshareddata/xcschemes/IBMCloudAppID.xcscheme": [ + { + "hashed_secret": "7a6c65d59dd755516d128f858acef861c012f568", + "is_verified": true, + "line_number": 36, + "type": "Hex High Entropy String", + "verified_result": null + }, + { + "hashed_secret": "933976b211f94b04e991cf7336413cdfcba10be2", + "is_verified": true, + "line_number": 86, + "type": "Hex High Entropy String", + "verified_result": null + } + ], + "IBMCloudAppID.xcodeproj/xcshareddata/xcschemes/IBMCloudAppIDTests.xcscheme": [ + { + "hashed_secret": "7a6c65d59dd755516d128f858acef861c012f568", + "is_verified": true, + "line_number": 20, + "type": "Hex High Entropy String", + "verified_result": null + } + ], + "IBMCloudAppIDTests/AppIDTestConstants.swift": [ + { + "hashed_secret": "40339a2a9cc4a6fa8f04ffa3b49bcd16da57d365", + "is_verified": true, + "line_number": 14, + "type": "Base64 High Entropy String", + "verified_result": null + }, + { + "hashed_secret": "cc394c02a16b73f61b97dae87b4f6f0a15cfb383", + "is_verified": true, + "line_number": 16, + "type": "Base64 High Entropy String", + "verified_result": null + }, + { + "hashed_secret": "9bbded2f5992731b503fbb7a6b55c61d99f80284", + "is_verified": true, + "line_number": 18, + "type": "JSON Web Token", + "verified_result": null + }, + { + "hashed_secret": "79baa980a80db7c722760e1e0adf84c0dcb79766", + "is_verified": true, + "line_number": 20, + "type": "JSON Web Token", + "verified_result": null + }, + { + "hashed_secret": "8e6cb178172ecaf84deafc91acd425e677cf8ed7", + "is_verified": true, + "line_number": 22, + "type": "JSON Web Token", + "verified_result": null + }, + { + "hashed_secret": "331a3997867a0f80867b4bb932e23b0f9bfa0e97", + "is_verified": true, + "line_number": 24, + "type": "JSON Web Token", + "verified_result": null + }, + { + "hashed_secret": "5e408fee53a6064a92f03f8adb2d822dfcc7aa8c", + "is_verified": true, + "line_number": 32, + "type": "JSON Web Token", + "verified_result": null + }, + { + "hashed_secret": "4ba7c215213a4e0d9fa54bc072509a2e354ca549", + "is_verified": true, + "line_number": 34, + "type": "JSON Web Token", + "verified_result": null + }, + { + "hashed_secret": "d62205c08edbf986b4892db672cca8471959f15d", + "is_verified": true, + "line_number": 36, + "type": "JSON Web Token", + "verified_result": null + }, + { + "hashed_secret": "3fa8bd60699bed5fa604093bd65a9a58f0124c5b", + "is_verified": true, + "line_number": 38, + "type": "JSON Web Token", + "verified_result": null + }, + { + "hashed_secret": "325abe36e1225d31ec20cfa40c2c986b429e0e63", + "is_verified": true, + "line_number": 40, + "type": "Hex High Entropy String", + "verified_result": null + }, + { + "hashed_secret": "74d6f458ceb2e3fe4fc7c2ce61b27044168bd8d2", + "is_verified": true, + "line_number": 43, + "type": "JSON Web Token", + "verified_result": null + }, + { + "hashed_secret": "123f6edf27b299227975598493a3ce5f331896c7", + "is_verified": true, + "line_number": 50, + "type": "JSON Web Token", + "verified_result": null + } + ], + "IBMCloudAppIDTests/AuthorizationManagerTests.swift": [ + { + "hashed_secret": "e6f5d8bcdc360468e50059c0f136f8d00a6e5ba0", + "is_verified": true, + "line_number": 224, + "type": "JSON Web Token", + "verified_result": null + }, + { + "hashed_secret": "c19c8279d3a0b73656f342500847429e0418d2f1", + "is_verified": true, + "line_number": 346, + "type": "JSON Web Token", + "verified_result": null + }, + { + "hashed_secret": "f98211be0ab942cd8709f5d0a7ab07bfb85d6b39", + "is_verified": true, + "line_number": 346, + "type": "JSON Web Token", + "verified_result": null + }, + { + "hashed_secret": "8bb6118f8fd6935ad0876a3be34a717d32708ffd", + "is_verified": true, + "line_number": 799, + "type": "Secret Keyword", + "verified_result": null + } + ], + "IBMCloudAppIDTests/SecurityUtilsTests.swift": [ + { + "hashed_secret": "200866ca8ceb03217a524171b4c03c8f77520f09", + "is_verified": true, + "line_number": 75, + "type": "Base64 High Entropy String", + "verified_result": null + }, + { + "hashed_secret": "d6f23934e8c77ca9bd423985efe7318f0ff92d0e", + "is_verified": true, + "line_number": 91, + "type": "Base64 High Entropy String", + "verified_result": null + } + ], + "IBMCloudAppIDTests/TokenManagerTests.swift": [ + { + "hashed_secret": "619b59c1f7b2ad50dc5f1ef346a7bf27ae46213b", + "is_verified": true, + "line_number": 455, + "type": "Secret Keyword", + "verified_result": null + } + ], + "IBMCloudAppIDTests/UtilsTests.swift": [ + { + "hashed_secret": "5d88cf3bb5539ca64036bcee339ed12b1151845b", + "is_verified": true, + "line_number": 76, + "type": "Base64 High Entropy String", + "verified_result": null + }, + { + "hashed_secret": "6897fa8db62febf7d1fd558b319524c254596019", + "is_verified": true, + "line_number": 77, + "type": "Base64 High Entropy String", + "verified_result": null + } + ] + }, + "version": "0.13.1+ibm.34.dss", + "word_list": { + "file": null, + "hash": null + } +} From d4156e3c8f4815c82f5c23625ebb26e25fa486b0 Mon Sep 17 00:00:00 2001 From: John McCormack Date: Tue, 27 Apr 2021 11:20:04 +0100 Subject: [PATCH 2/3] ran audit --- .secrets.baseline | 77 +++++++++++++++++++++++++++++++---------------- 1 file changed, 51 insertions(+), 26 deletions(-) diff --git a/.secrets.baseline b/.secrets.baseline index 5eed283..224dd18 100644 --- a/.secrets.baseline +++ b/.secrets.baseline @@ -3,7 +3,7 @@ "files": "^.secrets.baseline$", "lines": null }, - "generated_at": "2021-04-26T15:08:22Z", + "generated_at": "2021-04-27T10:18:49Z", "plugins_used": [ { "name": "AWSKeyDetector" @@ -67,14 +67,16 @@ "IBMCloudAppID.xcodeproj/xcshareddata/xcschemes/IBMCloudAppID.xcscheme": [ { "hashed_secret": "7a6c65d59dd755516d128f858acef861c012f568", - "is_verified": true, + "is_secret": false, + "is_verified": false, "line_number": 36, "type": "Hex High Entropy String", "verified_result": null }, { "hashed_secret": "933976b211f94b04e991cf7336413cdfcba10be2", - "is_verified": true, + "is_secret": false, + "is_verified": false, "line_number": 86, "type": "Hex High Entropy String", "verified_result": null @@ -83,7 +85,8 @@ "IBMCloudAppID.xcodeproj/xcshareddata/xcschemes/IBMCloudAppIDTests.xcscheme": [ { "hashed_secret": "7a6c65d59dd755516d128f858acef861c012f568", - "is_verified": true, + "is_secret": false, + "is_verified": false, "line_number": 20, "type": "Hex High Entropy String", "verified_result": null @@ -92,91 +95,104 @@ "IBMCloudAppIDTests/AppIDTestConstants.swift": [ { "hashed_secret": "40339a2a9cc4a6fa8f04ffa3b49bcd16da57d365", - "is_verified": true, + "is_secret": false, + "is_verified": false, "line_number": 14, "type": "Base64 High Entropy String", "verified_result": null }, { "hashed_secret": "cc394c02a16b73f61b97dae87b4f6f0a15cfb383", - "is_verified": true, + "is_secret": false, + "is_verified": false, "line_number": 16, "type": "Base64 High Entropy String", "verified_result": null }, { "hashed_secret": "9bbded2f5992731b503fbb7a6b55c61d99f80284", - "is_verified": true, + "is_secret": false, + "is_verified": false, "line_number": 18, "type": "JSON Web Token", "verified_result": null }, { "hashed_secret": "79baa980a80db7c722760e1e0adf84c0dcb79766", - "is_verified": true, + "is_secret": false, + "is_verified": false, "line_number": 20, "type": "JSON Web Token", "verified_result": null }, { "hashed_secret": "8e6cb178172ecaf84deafc91acd425e677cf8ed7", - "is_verified": true, + "is_secret": false, + "is_verified": false, "line_number": 22, "type": "JSON Web Token", "verified_result": null }, { "hashed_secret": "331a3997867a0f80867b4bb932e23b0f9bfa0e97", - "is_verified": true, + "is_secret": false, + "is_verified": false, "line_number": 24, "type": "JSON Web Token", "verified_result": null }, { "hashed_secret": "5e408fee53a6064a92f03f8adb2d822dfcc7aa8c", - "is_verified": true, + "is_secret": false, + "is_verified": false, "line_number": 32, "type": "JSON Web Token", "verified_result": null }, { "hashed_secret": "4ba7c215213a4e0d9fa54bc072509a2e354ca549", - "is_verified": true, + "is_secret": false, + "is_verified": false, "line_number": 34, "type": "JSON Web Token", "verified_result": null }, { "hashed_secret": "d62205c08edbf986b4892db672cca8471959f15d", - "is_verified": true, + "is_secret": false, + "is_verified": false, "line_number": 36, "type": "JSON Web Token", "verified_result": null }, { "hashed_secret": "3fa8bd60699bed5fa604093bd65a9a58f0124c5b", - "is_verified": true, + "is_secret": false, + "is_verified": false, "line_number": 38, "type": "JSON Web Token", "verified_result": null }, { "hashed_secret": "325abe36e1225d31ec20cfa40c2c986b429e0e63", - "is_verified": true, + "is_secret": false, + "is_verified": false, "line_number": 40, "type": "Hex High Entropy String", "verified_result": null }, { "hashed_secret": "74d6f458ceb2e3fe4fc7c2ce61b27044168bd8d2", - "is_verified": true, + "is_secret": false, + "is_verified": false, "line_number": 43, "type": "JSON Web Token", "verified_result": null }, { "hashed_secret": "123f6edf27b299227975598493a3ce5f331896c7", - "is_verified": true, + "is_secret": false, + "is_verified": false, "line_number": 50, "type": "JSON Web Token", "verified_result": null @@ -185,28 +201,32 @@ "IBMCloudAppIDTests/AuthorizationManagerTests.swift": [ { "hashed_secret": "e6f5d8bcdc360468e50059c0f136f8d00a6e5ba0", - "is_verified": true, + "is_secret": false, + "is_verified": false, "line_number": 224, "type": "JSON Web Token", "verified_result": null }, { "hashed_secret": "c19c8279d3a0b73656f342500847429e0418d2f1", - "is_verified": true, + "is_secret": false, + "is_verified": false, "line_number": 346, "type": "JSON Web Token", "verified_result": null }, { "hashed_secret": "f98211be0ab942cd8709f5d0a7ab07bfb85d6b39", - "is_verified": true, + "is_secret": false, + "is_verified": false, "line_number": 346, "type": "JSON Web Token", "verified_result": null }, { "hashed_secret": "8bb6118f8fd6935ad0876a3be34a717d32708ffd", - "is_verified": true, + "is_secret": false, + "is_verified": false, "line_number": 799, "type": "Secret Keyword", "verified_result": null @@ -215,14 +235,16 @@ "IBMCloudAppIDTests/SecurityUtilsTests.swift": [ { "hashed_secret": "200866ca8ceb03217a524171b4c03c8f77520f09", - "is_verified": true, + "is_secret": false, + "is_verified": false, "line_number": 75, "type": "Base64 High Entropy String", "verified_result": null }, { "hashed_secret": "d6f23934e8c77ca9bd423985efe7318f0ff92d0e", - "is_verified": true, + "is_secret": false, + "is_verified": false, "line_number": 91, "type": "Base64 High Entropy String", "verified_result": null @@ -231,7 +253,8 @@ "IBMCloudAppIDTests/TokenManagerTests.swift": [ { "hashed_secret": "619b59c1f7b2ad50dc5f1ef346a7bf27ae46213b", - "is_verified": true, + "is_secret": false, + "is_verified": false, "line_number": 455, "type": "Secret Keyword", "verified_result": null @@ -240,14 +263,16 @@ "IBMCloudAppIDTests/UtilsTests.swift": [ { "hashed_secret": "5d88cf3bb5539ca64036bcee339ed12b1151845b", - "is_verified": true, + "is_secret": false, + "is_verified": false, "line_number": 76, "type": "Base64 High Entropy String", "verified_result": null }, { "hashed_secret": "6897fa8db62febf7d1fd558b319524c254596019", - "is_verified": true, + "is_secret": false, + "is_verified": false, "line_number": 77, "type": "Base64 High Entropy String", "verified_result": null From 68e2c15913f5bd664139da84ea766333fdda3ca5 Mon Sep 17 00:00:00 2001 From: John McCormack Date: Thu, 3 Jun 2021 14:53:50 +0100 Subject: [PATCH 3/3] rescanned --- .secrets.baseline | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.secrets.baseline b/.secrets.baseline index 224dd18..7f79889 100644 --- a/.secrets.baseline +++ b/.secrets.baseline @@ -3,7 +3,7 @@ "files": "^.secrets.baseline$", "lines": null }, - "generated_at": "2021-04-27T10:18:49Z", + "generated_at": "2021-06-03T13:53:19Z", "plugins_used": [ { "name": "AWSKeyDetector"