False Positive: Hugging Face Access Token #10029
pascal-pfeiffer
started this conversation in
False Detection
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
IDs
Hugging Face Access Token
Description
Running
uvwith the--compile-bytecodeflag produces compiled pyc files from the source files. For thevllmpython package, these following files are flagged to contain theHugging Face Access Token.I believe this is a false positive detection due to rather loose regex to detect these
https://github.com/aquasecurity/trivy/blob/main/pkg/fanal/secret/builtin-rules.go#L178
FYI:
Link of
is broken.
Reproduction Steps
Target
Container Image
Scanner
Secret
Target OS
No response
Debug Output
Version
Checklist
-f jsonthat shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions