A tool for secrets management, encryption as a service, and privileged access management
649 matches across 12 categories. Click a row to expand file-level details.
| Severity | File | Line | Snippet |
|---|---|---|---|
| LOW | ui/.copywrite.hcl | 1 | # (OPTIONAL) Overrides the copywrite config schema version |
| LOW | ui/app/utils/openapi-helpers.ts | 381 | // [key: string]: string[]; |
| LOW | ui/app/utils/metrics-helpers.ts | 61 | for (const detail of metric.metric_data?.metric_details ?? []) { |
| LOW | ui/app/macros/lazy-capabilities.js | 1 | /** |
| LOW | ui/app/services/permissions.js | 181 | const currentNs = this.namespace.path; |
| LOW | ui/app/services/permissions.js | 301 | } |
| LOW | ui/app/services/permissions.js | 341 | |
| LOW | ui/app/services/permissions.js | 381 | // Resolution rule across matchers: |
| LOW | ui/app/services/permissions.js | 401 | // Now check capability satisfaction across the best exact/glob |
| LOW | …omponents/kubernetes/page/role/create-and-edit-test.js | 181 | await click('[data-test-radio-card="full"]'); |
| LOW | ui/tests/helpers/index.js | 21 | // |
| LOW | ui/tests/helpers/secret-engine/secret-engine-helpers.js | 361 | // { |
| LOW | ui/lib/core/addon/utils/all-engines-metadata.ts | 321 | }, |
| LOW | ui/lib/core/addon/utils/all-engines-metadata.ts | 341 | // { |
| LOW | ui/lib/kubernetes/addon/utils/generated-role-rules.js | 1 | /** |
| LOW | ui/lib/pki/addon/components/pki-issuer-cross-sign.js | 181 | // before and after. Recovery would be on the operator in this case; |
| LOW | serviceregistration/service_registration.go | 41 | // complete. The redirectAddr is an optional parameter for implementations |
| LOW | serviceregistration/service_registration.go | 61 | // |
| LOW | serviceregistration/service_registration.go | 81 | // If errors are returned, Vault only logs a warning, so it is |
| LOW | serviceregistration/service_registration.go | 101 | // configuration has been reloaded. |
| LOW | …viceregistration/consul/consul_service_registration.go | 421 | // Use a reactor pattern to handle and dispatch events to singleton |
| LOW | serviceregistration/kubernetes/testing/testserver.go | 61 | |
| LOW | serviceregistration/kubernetes/client/config.go | 21 | // The client itself does nothing directly with these variables, it's |
| LOW | serviceregistration/kubernetes/client/config.go | 81 | // The CACertPool is promoted to the top level from being originally on the TLSClientConfig |
| LOW | …eregistration/kubernetes/client/cmd/kubeclient/main.go | 1 | // Copyright IBM Corp. 2016, 2025 |
| LOW | enos/enos.vars.hcl | 1 | // Copyright IBM Corp. 2016, 2025 |
| LOW | enos/enos.vars.hcl | 21 | // aws_ssh_private_key_path = "./support/private_key.pem" |
| LOW | enos/enos.vars.hcl | 41 | // distro_version_rhel = "10.1" // or "8.10" or "9.7" |
| LOW | enos/enos.vars.hcl | 61 | // ui_run_tests sets whether to run the UI tests or not for the ui scenario. If set to false a |
| LOW | enos/enos.vars.hcl | 81 | // will be enabled. The netcat program is run in listening mode to provide an endpoint |
| LOW | enos/enos.vars.hcl | 101 | |
| LOW | enos/modules/start_vault/main.tf | 141 | # |
| LOW | enos/modules/build_local/main.tf | 1 | # Copyright IBM Corp. 2016, 2025 |
| LOW | enos/modules/build_local/scripts/build.sh | 1 | #!/usr/bin/env bash |
| LOW | enos/modules/target_ec2_spot_fleet/main.tf | 361 | # from 2-4 vCPUs and 4-16GB of RAM. We intentionally have a wide range |
| LOW | enos/modules/target_ec2_fleet/main.tf | 261 | |
| LOW | …s/modules/verify_secrets_engines/modules/create/ssh.tf | 1 | # Copyright IBM Corp. 2016, 2025 |
| LOW | tools/tools.go | 1 | // Copyright IBM Corp. 2016, 2025 |
| LOW | …nternal/pkg/github/close_copied_origin_pull_request.go | 41 | // |
| LOW | tools/pipeline/internal/pkg/github/create_backport.go | 21 | libgit "github.com/hashicorp/vault/tools/pipeline/internal/pkg/git/client" |
| LOW | tools/pipeline/internal/pkg/github/create_backport.go | 41 | // excluded CE files, or whether or not the backport can be skipped entirely. |
| LOW | tools/pipeline/internal/pkg/github/create_backport.go | 61 | // We use this to determine which branches are active so that we can |
| LOW | tools/pipeline/internal/pkg/github/create_backport.go | 221 | req.BackportLabelPrefix = prefix |
| LOW | tools/pipeline/internal/pkg/github/create_backport.go | 241 | // we'll create the CE backports. |
| LOW | tools/pipeline/internal/pkg/github/create_backport.go | 881 | |
| LOW | tools/pipeline/internal/pkg/git/client/client.go | 141 | // - relying on preconfigured gitconfig |
| LOW | .release/pipeline.hcl | 1 | # Copyright IBM Corp. 2016, 2025 |
| LOW | .release/docker/docker-entrypoint.sh | 1 | #!/usr/bin/dumb-init /bin/sh |
| LOW | .release/linux/package/etc/vault.d/vault.hcl | 21 | #listener "tcp" { |
| LOW | .release/linux/package/etc/vault.d/vault.hcl | 41 | #} |
| LOW | …database/cassandra/test-fixtures/no_tls/cassandra.yaml | 1 | # Copyright IBM Corp. 2016, 2025 |
| LOW | …database/cassandra/test-fixtures/no_tls/cassandra.yaml | 21 | # and will use the initial_token as described below. |
| LOW | …database/cassandra/test-fixtures/no_tls/cassandra.yaml | 41 | # initial_token allows you to specify tokens manually. While you can use it with |
| LOW | …database/cassandra/test-fixtures/no_tls/cassandra.yaml | 61 | |
| LOW | …database/cassandra/test-fixtures/no_tls/cassandra.yaml | 81 | |
| LOW | …database/cassandra/test-fixtures/no_tls/cassandra.yaml | 101 | # - AllowAllAuthenticator performs no checks - set it to disable authentication. |
| LOW | …database/cassandra/test-fixtures/no_tls/cassandra.yaml | 121 | # IRoleManager require an authenticated login, so unless the configured IAuthenticator |
| LOW | …database/cassandra/test-fixtures/no_tls/cassandra.yaml | 141 | # Defaults to the same value as roles_validity_in_ms. |
| LOW | …database/cassandra/test-fixtures/no_tls/cassandra.yaml | 161 | # be automatically used and so the following settings will have no effect. |
| LOW | …database/cassandra/test-fixtures/no_tls/cassandra.yaml | 181 | # same partitioner you were already using. |
| 420 more matches not shown… | |||
| Severity | File | Line | Snippet |
|---|---|---|---|
| MEDIUM | ui/tests/unit/utils/external-plugin-helpers-test.js | 207 | // This verifies that the reverse lookup algorithm is robust |
| MEDIUM | ui/tests/acceptance/policy/index-test.js | 136 | // List of policies can get long quickly -- filter for the policy to make the test more robust |
| MEDIUM | enos/enos-dev-scenario-single-cluster.hcl | 15 | // The matrix is where we define all the baseline combinations that enos can utilize to customize |
| MEDIUM | enos/enos-dev-scenario-pr-replication.hcl | 16 | // The matrix is where we define all the baseline combinations that enos can utilize to customize |
| MEDIUM | tools/pipeline/internal/pkg/github/doc.go | 4 | // Package github contains our implementation of pipeline sub-command requests that utilize Github |
| MEDIUM | tools/pipeline/internal/pkg/git/doc.go | 4 | // Package git implements various pipeline requests that utilize a local git client |
| MEDIUM | http/handler.go | 148 | // tokens provides a robust safeguard against malicious inputs without interfering |
| MEDIUM | sdk/helper/jsonutil/json_test.go | 458 | // A robust parser should reject any invalid escape sequence, not just unicode. |
| MEDIUM | sdk/helper/testcluster/util.go | 211 | // Be robust to multiple nodes thinking they are active. This is possible in |
| MEDIUM | sdk/helper/testcluster/util.go | 216 | // etc. so be robust against it. The best solution would be to have some sort |
| MEDIUM | scripts/copywrite-exceptions.sh | 5 | # then runs the copywrite bot to utilize local subdir config |
| MEDIUM | .github/actions/checkout/action.yml | 37 | # creates. Essentially, this SHA is the product of merging our PR into the merge target |
| MEDIUM | command/agent_test.go | 1491 | // Definitely not thread-safe, do not use t.Parallel with this. |
| MEDIUM | builtin/logical/database/path_roles.go | 992 | // user specified by Username. The credentials will leverage the existing |
| MEDIUM | builtin/logical/transit/path_datakey_test.go | 15 | // TestDataKeyWithPaddingScheme validates that we properly leverage padding scheme |
| MEDIUM | builtin/logical/pki/acme_wrappers.go | 106 | // acmeWrapper a basic wrapper that all ACME handlers should leverage as the basis. |
| MEDIUM | builtin/logical/pki/backend_test.go | 2808 | // that we will leverage the issuer's configured behavior |
| MEDIUM | builtin/logical/pki/backend_test.go | 6827 | // - Definitely will work with sign-verbatim. |
| MEDIUM | builtin/logical/pki/storage_migrations.go | 141 | // We always want to write out this log entry as the secondary clusters leverage this path to wake up |
| MEDIUM | builtin/logical/pki/issuing/context.go | 9 | // leverage to issue a certificate along with the |
| MEDIUM | vault/identity_store_injector_testonly.go | 31 | // Use of these endpoints is a bit nuanced as they are low level and do almost |
| MEDIUM | vault/token_store.go | 1283 | // minted service tokens. This function is meant to be robust so as to allow vault |
| MEDIUM | vault/identity_store_util.go | 971 | // ConflictResolver implementation, the behavior here is a bit nuanced. |
| Severity | File | Line | Snippet |
|---|---|---|---|
| LOW | …n/components/ldap/page/library/create-and-edit-test.js | 107 | const service_account_names = ['foo@bar.com', 'bar@baz.com']; |
| LOW | …onents/config-ui/messages/page/create-and-edit-test.js | 119 | 'Lorem ipsum dolor sit amet, consectetur adipiscing elit.' |
| LOW | …onents/config-ui/messages/page/create-and-edit-test.js | 119 | 'Lorem ipsum dolor sit amet, consectetur adipiscing elit.' |
| LOW | …onents/config-ui/messages/page/create-and-edit-test.js | 187 | 'Lorem ipsum dolor sit amet, consectetur adipiscing elit.' |
| LOW | …onents/config-ui/messages/page/create-and-edit-test.js | 187 | 'Lorem ipsum dolor sit amet, consectetur adipiscing elit.' |
| LOW | …onents/config-ui/messages/page/create-and-edit-test.js | 197 | .hasText('Lorem ipsum dolor sit amet, consectetur adipiscing elit.'); |
| LOW | …onents/config-ui/messages/page/create-and-edit-test.js | 197 | .hasText('Lorem ipsum dolor sit amet, consectetur adipiscing elit.'); |
| LOW | …onents/config-ui/messages/page/create-and-edit-test.js | 252 | 'Lorem ipsum dolor sit amet, consectetur adipiscing elit.' |
| LOW | …onents/config-ui/messages/page/create-and-edit-test.js | 252 | 'Lorem ipsum dolor sit amet, consectetur adipiscing elit.' |
| LOW | ui/tests/acceptance/config-ui/messages/messages-test.js | 54 | message = encodeString('Lorem ipsum dolor sit amet, consectetur adipiscing elit.'), |
| LOW | ui/tests/acceptance/config-ui/messages/messages-test.js | 54 | message = encodeString('Lorem ipsum dolor sit amet, consectetur adipiscing elit.'), |
| LOW | ui/tests/acceptance/config-ui/messages/messages-test.js | 101 | 'Lorem ipsum dolor sit amet, consectetur adipiscing elit.' |
| LOW | ui/tests/acceptance/config-ui/messages/messages-test.js | 101 | 'Lorem ipsum dolor sit amet, consectetur adipiscing elit.' |
| LOW | ui/tests/acceptance/config-ui/messages/messages-test.js | 275 | 'Lorem ipsum dolor sit amet, consectetur adipiscing elit.' |
| LOW | ui/tests/acceptance/config-ui/messages/messages-test.js | 275 | 'Lorem ipsum dolor sit amet, consectetur adipiscing elit.' |
| LOW | ui/tests/acceptance/config-ui/messages/messages-test.js | 296 | 'Lorem ipsum dolor sit amet, consectetur adipiscing elit.' |
| LOW | ui/tests/acceptance/config-ui/messages/messages-test.js | 296 | 'Lorem ipsum dolor sit amet, consectetur adipiscing elit.' |
| LOW | ui/tests/acceptance/config-ui/messages/messages-test.js | 375 | 'Lorem ipsum dolor sit amet, consectetur adipiscing elit.' |
| LOW | ui/tests/acceptance/config-ui/messages/messages-test.js | 375 | 'Lorem ipsum dolor sit amet, consectetur adipiscing elit.' |
| LOW | ui/tests/acceptance/config-ui/messages/messages-test.js | 396 | 'Lorem ipsum dolor sit amet, consectetur adipiscing elit.' |
| LOW | ui/tests/acceptance/config-ui/messages/messages-test.js | 396 | 'Lorem ipsum dolor sit amet, consectetur adipiscing elit.' |
| LOW | …ptance/config-ui/messages/messages-unauth-auth-test.js | 138 | 'Lorem ipsum dolor sit amet, consectetur adipiscing elit.' |
| LOW | …ptance/config-ui/messages/messages-unauth-auth-test.js | 138 | 'Lorem ipsum dolor sit amet, consectetur adipiscing elit.' |
| LOW | ui/mirage/handlers/custom-messages.js | 142 | 'Lorem ipsum dolor sit amet, consectetur adipiscing elit. Curabitur nulla augue, placerat quis risus bland |
| LOW | ui/mirage/handlers/custom-messages.js | 142 | 'Lorem ipsum dolor sit amet, consectetur adipiscing elit. Curabitur nulla augue, placerat quis risus bland |
| LOW | ui/mirage/handlers/custom-messages.js | 152 | 'Lorem ipsum dolor sit amet, consectetur adipiscing elit. Curabitur nulla augue, placerat quis risus bland |
| LOW | ui/mirage/handlers/custom-messages.js | 152 | 'Lorem ipsum dolor sit amet, consectetur adipiscing elit. Curabitur nulla augue, placerat quis risus bland |
| LOW | …pipeline/internal/pkg/github/copy_pull_request_test.go | 27 | Name: libgithub.Ptr("John Doe"), |
| LOW | …pipeline/internal/pkg/github/copy_pull_request_test.go | 36 | Name: libgithub.Ptr("John Doe"), |
| LOW | …pipeline/internal/pkg/github/copy_pull_request_test.go | 40 | Name: libgithub.Ptr("John Doe"), |
| LOW | …pipeline/internal/pkg/github/copy_pull_request_test.go | 49 | Name: libgithub.Ptr("John Doe"), |
| LOW | …pipeline/internal/pkg/github/copy_pull_request_test.go | 53 | Name: libgithub.Ptr("Jane Doe"), |
| LOW | …pipeline/internal/pkg/github/copy_pull_request_test.go | 62 | Name: libgithub.Ptr("John Doe"), |
| LOW | …pipeline/internal/pkg/github/copy_pull_request_test.go | 66 | Name: libgithub.Ptr("Jane Doe"), |
| LOW | …pipeline/internal/pkg/github/copy_pull_request_test.go | 70 | Name: libgithub.Ptr("Jane Doe"), |
| LOW | …pipeline/internal/pkg/github/copy_pull_request_test.go | 74 | Name: libgithub.Ptr("John Doe"), |
| LOW | tools/pipeline/internal/pkg/git/client/opts_test.go | 836 | Author: "John Doe", |
| LOW | builtin/logical/pki/cert_util_test.go | 526 | EmailAddresses: []string{"admin@example.com", "user@example.com"}, |
| LOW | builtin/logical/pki/cert_util_test.go | 526 | EmailAddresses: []string{"admin@example.com", "user@example.com"}, |
| LOW | builtin/logical/pki/cert_util_test.go | 547 | PermittedEmailAddresses: []string{"info@example.com", "user@example.com", "admin@example.com"}, |
| LOW | builtin/logical/pki/cert_util_test.go | 547 | PermittedEmailAddresses: []string{"info@example.com", "user@example.com", "admin@example.com"}, |
| LOW | builtin/logical/pki/cert_util_test.go | 628 | EmailAddresses: []string{"admin@example.com", "user@example.com"}, |
| LOW | builtin/logical/pki/cert_util_test.go | 628 | EmailAddresses: []string{"admin@example.com", "user@example.com"}, |
| LOW | builtin/logical/pki/cert_util_test.go | 1012 | EmailAddresses: []string{"admin@example.com", "user@example.com"}, |
| LOW | builtin/logical/pki/cert_util_test.go | 1012 | EmailAddresses: []string{"admin@example.com", "user@example.com"}, |
| LOW | builtin/logical/pki/cert_util_test.go | 1098 | EmailAddresses: []string{"admin@example.com", "user@example.com"}, |
| LOW | builtin/logical/pki/cert_util_test.go | 1098 | EmailAddresses: []string{"admin@example.com", "user@example.com"}, |
| LOW | vault/identity_store_conflicts_test.go | 411 | Name: "user@example.com", |
| LOW | vault/identity_store_conflicts_test.go | 419 | Name: "user@example.com", |
| Severity | File | Line | Snippet |
|---|---|---|---|
| MEDIUM | enos/enos-dynamic-config.hcl | 6 | # This file is overwritten in CI as it contains branch specific and sometimes ever-changing values. |
| MEDIUM | …mark/set_up_telemetry_collector/scripts/run-grafana.sh | 86 | # Create a function to process each dashboard file |
| MEDIUM | …mark/set_up_telemetry_collector/scripts/run-grafana.sh | 93 | # Create a temporary file |
| MEDIUM | …dules/softhsm_create_vault_keys/scripts/create-keys.sh | 27 | # Create an HSM slot and return the slot number in decimal value. |
| MEDIUM | …es/verify_log_secrets/scripts/scan_logs_for_secrets.sh | 37 | # Create a readable copy of the audit log. |
| MEDIUM | …es/verify_log_secrets/scripts/scan_logs_for_secrets.sh | 46 | # Create a radar index file of our KVv2 secret values. |
| MEDIUM | …rify_secrets_engines/scripts/pki-issue-certificates.sh | 39 | # Creating a role |
| MEDIUM | …rify_secrets_engines/scripts/pki-issue-certificates.sh | 54 | # Creating a intermediate role |
| MEDIUM | …/verify_secrets_engines/scripts/ldap/verify-secrets.sh | 122 | # Create the dynamic LDAP role in Vault using the LDIF templates |
| MEDIUM | …/verify_secrets_engines/scripts/ldap/verify-secrets.sh | 167 | # Create a different password policy (strong-policy) |
| MEDIUM | …s/scripts/ldap/Dynamic-roles/dynamic-roles-deletion.sh | 121 | # Define the check function |
| MEDIUM | …os/modules/verify_secrets_engines/modules/create/kv.tf | 56 | # Create a group policy that allows writing to our kv store |
| MEDIUM | …/modules/verify_secrets_engines/modules/create/auth.tf | 76 | # Create a default policy for our users that allows them to read and list. |
| MEDIUM | …les/verify_secrets_engines/modules/create/ldap/ldap.tf | 197 | # Create a new Library set of service accounts |
| MEDIUM | …_operation_token/scripts/configure-vault-dr-primary.sh | 19 | # Define the policy content |
| MEDIUM | …_operation_token/scripts/configure-vault-dr-primary.sh | 49 | # Create a token for the failover handler role and output the token only |
| MEDIUM | .github/workflows/ci.yml | 135 | # Initialize a variable to collect matched versions |
| MEDIUM | .github/scripts/report-build-status.sh | 31 | # Create a comment body to set on the pull request which reports failed jobs with a url to the |
| MEDIUM | .github/actions/install-tools/action.yml | 29 | # Create the tool cache directory if it doesn't exist and add it to the |
| Severity | File | Line | Snippet |
|---|---|---|---|
| LOW | …/integration/components/page/namespaces-wizard-test.js | 55 | // Step 1: Choose security policy |
| LOW | …/integration/components/page/namespaces-wizard-test.js | 61 | // Step 2: Add namespace data |
| LOW | …/integration/components/page/namespaces-wizard-test.js | 67 | // Step 3: Choose implementation method |
| LOW | …/integration/components/page/namespaces-wizard-test.js | 76 | // Step 1: Choose flexible policy |
| LOW | …crets_engines/scripts/ldap-library-checkin-specific.sh | 28 | # Step 1: Check out an account to prepare for check-in test |
| LOW | …crets_engines/scripts/ldap-library-checkin-specific.sh | 41 | # Step 2: Check in the specific account by name |
| LOW | …_secrets_engines/scripts/ldap-library-force-checkin.sh | 29 | # Step 1: Check out an account to prepare for force check-in test |
| LOW | …_secrets_engines/scripts/ldap-library-force-checkin.sh | 42 | # Step 2: Admin force check-in via /manage/ endpoint |
| LOW | …rets_engines/scripts/ldap-library-password-rotation.sh | 46 | # Step 1: Checkout an account to get initial password |
| LOW | …rets_engines/scripts/ldap-library-password-rotation.sh | 61 | # Step 2: Check-in the account (this should trigger password rotation) |
| LOW | …rets_engines/scripts/ldap-library-password-rotation.sh | 96 | # Step 3: Checkout again to get new password |
| LOW | …rets_engines/scripts/ldap-library-password-rotation.sh | 111 | # Step 4: Verify password rotation |
| LOW | …rets_engines/scripts/ldap-library-password-rotation.sh | 124 | # Step 5: Check in the second account so it's available for subsequent tests |
| LOW | physical/foundationdb/fdb-go-install.sh | 193 | # Step 1: Make sure repository is present. |
| LOW | physical/foundationdb/fdb-go-install.sh | 237 | # Step 2: Build generated things. |
| LOW | physical/foundationdb/fdb-go-install.sh | 268 | # Step 3: Add to go path. |
| LOW | physical/foundationdb/fdb-go-install.sh | 302 | # Step 4: Build the binaries. |
| LOW | physical/foundationdb/fdb-go-install.sh | 319 | # Step 5: Explain CGO flags. |
| LOW | sdk/logical/token.go | 183 | // Step 1: Copy entry policies to a new struct |
| LOW | sdk/logical/token.go | 187 | // Step 2: Sort and join copied policies |
| LOW | sdk/logical/token.go | 194 | // Step 3: Add namespace ID |
| LOW | sdk/logical/token.go | 201 | // Step 4: Remove the first character in the string, as it's an unnecessary delimiter |
| LOW | sdk/logical/token.go | 204 | // Step 5: Hash the sum |
| LOW | vault/core_metrics.go | 434 | // Therefore, we need to check if c.mounts is nil. If we do not, this will panic when |
| LOW | vault/core_metrics.go | 495 | // Therefore, we need to check if c.mounts is nil. If we do not, this will panic when |
| Severity | File | Line | Snippet |
|---|---|---|---|
| MEDIUM | ui/tests/unit/services/permissions-test.js | 51 | // ─────────────────────────────────────────────────────────────────────────── |
| MEDIUM | ui/tests/unit/services/permissions-test.js | 53 | // ─────────────────────────────────────────────────────────────────────────── |
| MEDIUM | ui/tests/unit/services/permissions-test.js | 71 | // ─────────────────────────────────────────────────────────────────────────── |
| MEDIUM | ui/tests/unit/services/permissions-test.js | 73 | // ─────────────────────────────────────────────────────────────────────────── |
| MEDIUM | ui/tests/unit/services/permissions-test.js | 289 | // ─────────────────────────────────────────────────────────────────────────── |
| MEDIUM | ui/tests/unit/services/permissions-test.js | 291 | // ─────────────────────────────────────────────────────────────────────────── |
| MEDIUM | ui/tests/unit/services/permissions-test.js | 687 | // ─────────────────────────────────────────────────────────────────────────── |
| MEDIUM | ui/tests/unit/services/permissions-test.js | 689 | // ─────────────────────────────────────────────────────────────────────────── |
| MEDIUM | enos/enos-scenario-dr-replication.hcl | 768 | # ================================================ |
| MEDIUM | enos/enos-scenario-dr-replication.hcl | 770 | # ================================================ |
| MEDIUM | enos/enos-scenario-dr-replication.hcl | 992 | # ============================== |
| MEDIUM | enos/enos-scenario-dr-replication.hcl | 994 | # ============================== |
| Severity | File | Line | Snippet |
|---|---|---|---|
| LOW | …mark/set_up_telemetry_collector/scripts/run-grafana.sh | 52 | # Check if the response contains the UID |
| LOW | …ify_billing_start_date/scripts/verify-billing-start.sh | 55 | # Verify if the billing start date is in the latest billing year |
| LOW | enos/modules/verify_secrets_engines/scripts/write.sh | 23 | # Check if PAYLOAD is empty or unset |
| LOW | …ify_secrets_engines/scripts/ldap/verify-audit-trail.sh | 22 | # Check if audit log file exists |
| LOW | …os/modules/vault_run_blackbox_test/scripts/run-test.sh | 21 | # Check if Go is installed |
| LOW | …os/modules/vault_run_blackbox_test/scripts/run-test.sh | 35 | # Check if gotestsum is installed (required) |
| LOW | …os/modules/vault_run_blackbox_test/scripts/run-test.sh | 47 | # Check if jq is available (needed for parsing test matrix) |
| LOW | …os/modules/vault_run_blackbox_test/scripts/run-test.sh | 52 | # Check if git is available (needed for git rev-parse) |
| LOW | …os/modules/vault_run_blackbox_test/scripts/run-test.sh | 121 | # Check if JSON file was created successfully |
| LOW | …os/modules/vault_run_blackbox_test/scripts/run-test.sh | 126 | # Check if JUnit file was created (only when using gotestsum) |
| LOW | scripts/gen_openapi.sh | 92 | # Check if vault version contains +ent |
| LOW | .github/workflows/changelog-checker.yml | 28 | # Check if there is a diff in the changelog directory. |
| LOW | .github/workflows/test-go.yml | 535 | # Check if test results contains offending phrase |
| LOW | .github/scripts/report-ci-status.sh | 31 | # Check if the number of failures is greater than the maximum tests to display |
| Severity | File | Line | Snippet |
|---|---|---|---|
| MEDIUM | …omponents/kubernetes/page/role/create-and-edit-test.js | 184 | const expectedInitialValue = `# The below is an example that you can use as a starting point. |
| MEDIUM | ui/lib/kubernetes/addon/utils/generated-role-rules.js | 6 | const example = `# The below is an example that you can use as a starting point. |
| MEDIUM | enos/enos-scenario-benchmark.hcl | 10 | If you've never used Enos before, it's worth noting that the matrix parameters act as filters. You can view a full |
| MEDIUM | …database/cassandra/test-fixtures/no_tls/cassandra.yaml | 41 | # initial_token allows you to specify tokens manually. While you can use it with |
| MEDIUM | …database/cassandra/test-fixtures/no_tls/cassandra.yaml | 629 | # you may want to adjust max_value_size_in_mb accordingly. |
| LOW | …database/cassandra/test-fixtures/no_tls/cassandra.yaml | 844 | # Warning: before enabling this property make sure to ntp is installed |
| MEDIUM | builtin/logical/pki/chain_util.go | 546 | // not sufficient as discussed above -- we also need to find any |
| LOW | vault/identity_store_entities.go | 1085 | // Don't forget to insert aliases into alias table that were part of |
| Severity | File | Line | Snippet |
|---|---|---|---|
| LOW | ui/app/utils/mfa-login-enforcement-helpers.js | 188 | export async function fetchMfaLoginEnforcements(api) { |
| LOW | ui/app/utils/plugin-catalog-helpers.ts | 73 | export function enhanceEnginesWithCatalogData( |
| LOW | ui/app/utils/plugin-catalog-helpers.ts | 199 | export function categorizeEnginesByStatus(engines: EnhancedEngineDisplayData[]): CategorizedEngines { |
| LOW | ui/app/utils/plugin-catalog-helpers.ts | 214 | export function getPluginVersionsFromEngineType(list: PluginCatalogPlugin[] | undefined, name: string) { |
| LOW | ui/app/utils/plugin-catalog-helpers.ts | 253 | export function getAllVersionsForEngineType( |
| LOW | ui/app/utils/version-utils.ts | 120 | export function isPluginVersionValidForType(pluginType: string, pluginVersion?: string): boolean { |
| LOW | ui/app/utils/external-plugin-helpers.ts | 41 | export function getBuiltinTypeFromExternalPlugin(externalPluginName: string): string | undefined { |
| LOW | ui/app/utils/external-plugin-helpers.ts | 74 | export function getExternalPluginNameFromBuiltin(builtinType: string): string | null { |
| LOW | ui/app/utils/model-helpers/secret-engine-helpers.ts | 25 | function getTransformModelTypeFromSecretPath(secret: string): string { |
| LOW | ui/app/utils/model-helpers/secret-engine-helpers.ts | 43 | function getTransformModelTypeFromParams(transformType?: string): string { |
| LOW | ui/app/helpers/exit-configuration-route.ts | 18 | function getExitConfigurationRoute(engineType: string, version?: number): string { |
| LOW | ui/app/helpers/supported-managed-auth-backends.js | 12 | export function supportedManagedAuthBackends() { |
| LOW | ui/lib/core/addon/utils/all-engines-metadata.ts | 45 | export function filterEnginesByMountCategory({ |
| LOW | …lib/core/addon/helpers/replication-mode-description.js | 14 | function replicationModeDescription([mode]) { |
| LOW | ui/e2e/tests/superuser/sync-destinations.spec.ts | 19 | async function openCreateDestinationForm(page: Page, type: string) { |
| Severity | File | Line | Snippet |
|---|---|---|---|
| CRITICAL | ui/tests/acceptance/raft-storage-test.js | 32 | this.config.data.config.servers.pop(); |
| Severity | File | Line | Snippet |
|---|---|---|---|
| HIGH | builtin/logical/pki/path_generate_root_test.go | 80 | // Explicit positive values: pathLenConstraint is set as requested. |
| Severity | File | Line | Snippet |
|---|---|---|---|
| LOW | ui/tests/helpers/secret-engine/secret-engine-helpers.js | 359 | // Example usage |
| LOW | scripts/deprecations-checker.sh | 6 | # Usage: |