-
Notifications
You must be signed in to change notification settings - Fork 525
Description
Greetings,
We are security researchers and we are looking for insecure coding patterns and configurations in the microservice architecture repositories. In your repository, we have found instances of hard-coded passwords. According to CWE, "A hard-coded password typically leads to a significant authentication failure that can be difficult for the system administrator to detect."
Hopefully, you agree and will fix it.
Source: https://github.com/livelessons-spring/building-microservices/blob/master/livelessons-testing/livelessons-testing-wiremock/src/main/resources/application.properties and https://github.com/livelessons-spring/building-microservices/blob/master/livelessons-security/livelessons-security-https/src/main/resources/application.yml and https://github.com/livelessons-spring/building-microservices/blob/master/livelessons-testing/livelessons-testing-spring/src/main/resources/application.properties