Repository navigation
docs(security): Token and Credential Format - #19631
Conversation
Docs on our legacy and existing credentials formats for make Sentry secrets identification simpler. Provides a first-party reference for secret scanners, agents, and incident responders.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
1 Skipped Deployment
|
|
|
||
| Other apps may rename variables, wrap values in their own config, or store tokens with none of these strings nearby, so treat this as a starting point. | ||
|
|
||
| ## Matching Caveats |
There was a problem hiding this comment.
Is this supposed to be the section that is explaining how false positives might appear? Or is it the sum of all the information being shared here? It's not super clear, though I'm not an SME in the space. Would this page benefit from a TL;DR or what in fact might cause false positives?
There was a problem hiding this comment.
A 32- or 64-character hex string is really generic on its own and I think the false positives here. I included the list of commons key names pulled from our own docs and source in the paragraph above, but that may not be the variable names others use so it's up to the folks scanning to reduce their own false positives with respect to generic formats.
sfanahata
left a comment
There was a problem hiding this comment.
👍 Not blocking, but left a comment asking for clarity, if it makes sense to add it.
## DESCRIBE YOUR PR Docs on our legacy and existing credentials formats for make Sentry secrets identification simpler. Provides a first-party reference for secret scanners, agents, and incident responders. ## IS YOUR CHANGE URGENT? Help us prioritize incoming PRs by letting us know when the change needs to go live. Select exactly one option. For deadlines, replace `YYYY-MM-DD` with the due date. You can update this information later by editing the PR description. - [X] No deadline: Not urgent, can wait up to 1 week+ ## SLA - Teamwork makes the dream work, so please add a reviewer to your PRs. - Please give the docs team up to 1 week to review your PR unless you've supplied a deadline. Thanks in advance for your help! ## PRE-MERGE CHECKLIST _Make sure you've checked the following before merging your changes:_ - [X] Checked Vercel preview for correctness, including links - [X] PR was reviewed and approved by any necessary SMEs (subject matter experts) - [ ] PR was reviewed and approved by a member of the [Sentry docs team](https://github.com/orgs/getsentry/teams/docs)
DESCRIBE YOUR PR
Docs on our legacy and existing credentials formats for make Sentry secrets identification simpler. Provides a first-party reference for secret scanners, agents, and incident responders.
IS YOUR CHANGE URGENT?
Help us prioritize incoming PRs by letting us know when the change needs to go live.
Select exactly one option. For deadlines, replace
YYYY-MM-DDwith the due date. You can update this information later by editing the PR description.SLA
Thanks in advance for your help!
PRE-MERGE CHECKLIST
Make sure you've checked the following before merging your changes: