1. https://appdevelopermagazine.com/security
  2. https://appdevelopermagazine.com/sourceclear-open-sources-tool-that-identifies-potentially-hazardous-commits/
6/13/2016 5:47:24 PM
SourceClear Open Sources Tool That Identifies Potentially Hazardous Commits
SSH Keys,API Tokens,AWS Credentials,Security Patches,Open Source
/SourceClear-App-Developer-Magazine_vskysmv2.jpg
App Developer Magazine
SourceClear Open Sources Tool That Identifies Potentially Hazardous Commits

Security

SourceClear Open Sources Tool That Identifies Potentially Hazardous Commits


Monday, June 13, 2016

Stuart Parkerson Stuart Parkerson


SourceClear has open sourced its Commit Watcher tool which identifies accidental disclosure of sensitive information (SSH keys, AWS credentials, etc.) and security patches for vulnerabilities that are not explicitly disclosed.

In a blog post the company commented, “We initially built Commit Watcher to discover these undisclosed (but public) security patches, which are fed into the Source Clear Registry once they have been verified. When we added the ability to find accidentally disclosed secrets in projects, we realized how valuable this tool can be for every company releasing open source software. Companies can watch their own projects, public and private, for accidental disclosures, and take remedial action as soon as possible.”

Commit Watcher ships with dozens of rules to find commits containing credentials from services like Amazon Web Services and Salesforce, to SSH keys, API tokens, database dump files, and more. The platform also looks for commits and commit messages that contain keywords that are often associated with security vulnerabilities.



Read more: https://github.com/srcclr/commit-watcher/




Subscribe to App Developer Magazine

Become a subscriber of App Developer Magazine for just $5.99 a month and take advantage of all these perks.

MEMBERS GET ACCESS TO

  • - Exclusive content from leaders in the industry
  • - Q&A articles from industry leaders
  • - Tips and tricks from the most successful developers weekly
  • - Monthly issues, including all 90+ back-issues since 2012
  • - Event discounts and early-bird signups
  • - Gain insight from top achievers in the app store
  • - Learn what tools to use, what SDK's to use, and more

    Subscribe here



Featured Stories


Spotify and UMG strike landmark AI music licensing deal
Spotify and UMG strike landmark AI music licensing deal Thursday, May 28, 2026


Anthropic investigation opened after Mythos accessed by Discord group
Anthropic investigation opened after Mythos accessed by Discord group Wednesday, May 27, 2026




AI layoffS: What is really behind it all
AI layoffS: What is really behind it all Tuesday, May 26, 2026


The identity system is failing under AI
The identity system is failing under AI Monday, May 25, 2026


The Real World Launches Expert-Verified AI Certification Framework
The Real World Launches Expert-Verified AI Certification Framework Friday, May 22, 2026


Multiple language options when developing apps with Evoke
Multiple language options when developing apps with Evoke Thursday, May 21, 2026


When Social Listening Becomes Social Surveillance
When Social Listening Becomes Social Surveillance Wednesday, May 20, 2026


Medical debt relief custom-built platform moopFi launches
Medical debt relief custom-built platform moopFi launches Tuesday, May 19, 2026


Quant Pros Say AI Is Widening the Skills Gap
Quant Pros Say AI Is Widening the Skills Gap Monday, May 18, 2026


Tether QVAC SDK Powers AI Across Devices and Platforms
Tether QVAC SDK Powers AI Across Devices and Platforms Wednesday, April 22, 2026


Stay Updated

Sign up for our newsletter for the headlines delivered to you

SuccessFull SignUp

Get More App News



/sites/themes/prod/assets/js/less.js"> ' ' %>