Skip to content

Security finding β€” possible Firebase service-account in source (details on request)Β #2

Description

@Raffa-jarrl

Hi πŸ‘‹

Automated scan from Lictor flagged a pattern that looks like a Firebase / Google service-account JSON in your public repo. I verified the pattern matches; I did not verify exploitability against your live project.

  • What I saw: a JSON block with "type":"service_account" + private_key_id shape.
  • Why it might matter: if real, this key grants full GCP/Firebase project access until manually revoked.
  • What to check: the file the scan flagged β€” reply here (or email Raffa@Lictor-AI.com) and I'll send the exact path + line privately. If it's a sample/test/already-revoked, just say so and I'll close out.

Either way β€” thank you for the work you do on this repo. πŸ™

β€” Raffa Β· Lictor (open-source, Apache 2.0)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions