Skip to content

Use a token format with a prefix #1475

Open
@nicwortel

Description

@nicwortel

Private Packagist uses a token format with a prefix and checksum to help with automated scanning for commited secrets in codebases.
For an example, see Trivy: Secret scanning and aquasecurity/trivy#7826.

Doing the same for Packagist.org would allow those secret scanners to scan for Packagist.org tokens as well.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions