← Scan another repo

github.com/thedotmack/claude-mem

@ f85bb28c4788

Submitted 8/4/2026, 10:25:54 AM · Status: ok

Risk grade
F
100 / 100
Findings
89
0 critical44 high42 medium3 low0 info0 on CISA KEV0ATT&CK
Showing 89 of 89 findings

Findings

  • Detected aws-access-token: Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms
    Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.
    gitleaks
  • Detected aws-access-token: Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms
    Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected jwt: Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data
    Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.
    gitleaks
  • Shell command built with interpolated input via child_process.exec — command injection risk. Use execFile with an argv array. (First-party socbox; Apache-2.0.)
    Shell command built with interpolated input via child_process.exec — command injection risk. Use execFile with an argv array. (First-party socbox; Apache-2.0.)
    semgrepworkers/sync-hub/src/do/SyncHub.ts:586
  • Shell command built with interpolated input via child_process.exec — command injection risk. Use execFile with an argv array. (First-party socbox; Apache-2.0.)
    Shell command built with interpolated input via child_process.exec — command injection risk. Use execFile with an argv array. (First-party socbox; Apache-2.0.)
    semgrepsrc/npx-cli/install/setup-runtime.ts:441
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgrepsrc/services/sqlite/SessionStore.ts:614
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgrepsrc/services/sqlite/SessionStore.ts:1397
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgrepsrc/services/telemetry/install-stats.ts:80
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgrepsrc/services/telemetry/install-stats.ts:33
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgrepsrc/services/telemetry/backfill.ts:462
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgrepsrc/services/telemetry/backfill.ts:452
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgrepsrc/services/telemetry/backfill.ts:409
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgrepsrc/services/telemetry/backfill.ts:393
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgrepsrc/services/telemetry/backfill.ts:374
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgrepsrc/services/telemetry/backfill.ts:341
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgrepsrc/services/telemetry/backfill.ts:326
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgrepsrc/services/telemetry/backfill.ts:304
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgrepsrc/services/telemetry/backfill.ts:284
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgrepsrc/services/telemetry/backfill.ts:270
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgrepsrc/services/telemetry/backfill.ts:256
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgrepsrc/services/telemetry/backfill.ts:234
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgrepsrc/services/telemetry/backfill.ts:220
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgrepplugin/sqlite/SessionStore.js:29
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgrepplugin/sqlite/SessionStore.js:29
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgrepplugin/sqlite/SessionStore.js:158
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgrepplugin/sqlite/SessionStore.js:158
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgrepplugin/sqlite/SessionStore.js:177
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgrepplugin/sqlite/SessionStore.js:177
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgrepplugin/sqlite/SessionStore.js:177
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgrepplugin/sqlite/SessionStore.js:475
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgrepsrc/services/sqlite/SessionStore.ts:126
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgrepsrc/services/sqlite/SessionStore.ts:131
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgrepsrc/services/sqlite/SessionStore.ts:464
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgrepsrc/services/sqlite/SessionStore.ts:495
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgrepsrc/services/sqlite/SessionStore.ts:594
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgrepsrc/services/sqlite/SessionStore.ts:608
  • 'apt-get' missing '--no-install-recommends'
    'apt-get' install should use '--no-install-recommends' to minimize image size.
    trivyDockerfile.test-installer:20
  • Image user should not be 'root'
    Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.
    trivyDockerfile.test-installer:0
  • Ensure that a user for the container has been created
    Ensure that a user for the container has been created on /Dockerfile.test-installer.
    checkovDockerfile.test-installer:1
  • Ensure that HEALTHCHECK instructions have been added to container images
    Ensure that HEALTHCHECK instructions have been added to container images on /openclaw/Dockerfile.e2e.
    checkovopenclaw/Dockerfile.e2e:1
  • Ensure that HEALTHCHECK instructions have been added to container images
    Ensure that HEALTHCHECK instructions have been added to container images on /Dockerfile.test-installer.
    checkovDockerfile.test-installer:1
  • Ensure that HEALTHCHECK instructions have been added to container images
    Ensure that HEALTHCHECK instructions have been added to container images on /docker/claude-mem/Dockerfile.
    checkovdocker/claude-mem/Dockerfile:1
  • Ensure that sudo isn't used
    Ensure that sudo isn't used on /Dockerfile.test-installer.RUN
    checkovDockerfile.test-installer:8
  • Ensure top-level permissions are not set to write-all
    Ensure top-level permissions are not set to write-all on on(Windows)
    checkov.github/workflows/windows.yml:0
  • Ensure top-level permissions are not set to write-all
    Ensure top-level permissions are not set to write-all on on(CI)
    checkov.github/workflows/ci.yml:0
  • Ensure top-level permissions are not set to write-all
    Ensure top-level permissions are not set to write-all on on(Claude Code)
    checkov.github/workflows/claude.yml:21
  • Ensure top-level permissions are not set to write-all
    Ensure top-level permissions are not set to write-all on on(Close Tracked Issues)
    checkov.github/workflows/close-tracked-issues.yml:26
  • Ensure top-level permissions are not set to write-all
    Ensure top-level permissions are not set to write-all on on(Convert Feature Requests to Discussions)
    checkov.github/workflows/convert-feature-requests.yml:20
  • Ensure top-level permissions are not set to write-all
    Ensure top-level permissions are not set to write-all on on(Deploy Install Scripts)
    checkov.github/workflows/deploy-install-scripts.yml:0
  • Ensure top-level permissions are not set to write-all
    Ensure top-level permissions are not set to write-all on on(Publish to npm)
    checkov.github/workflows/npm-publish.yml:0
  • The build output cannot be affected by user parameters other than the build entry point and the top-level source location. GitHub Actions workflow_dispatch inputs MUST be empty.
    The build output cannot be affected by user parameters other than the build entry point and the top-level source location. GitHub Actions workflow_dispatch inputs MUST be empty. on on(Close Tracked Issues)
    checkov.github/workflows/close-tracked-issues.yml:14
  • The build output cannot be affected by user parameters other than the build entry point and the top-level source location. GitHub Actions workflow_dispatch inputs MUST be empty.
    The build output cannot be affected by user parameters other than the build entry point and the top-level source location. GitHub Actions workflow_dispatch inputs MUST be empty. on on(Convert Feature Requests to Discussions)
    checkov.github/workflows/convert-feature-requests.yml:8
  • Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration
    grypeCVE-2026-47751EPSS 0.6%
  • brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
    ### Summary `expand()` bounds the *number* of results it produces (the `max` option, `100_000` by default) but not their *length*. By chaining many brace groups, an attacker keeps the result count under `max` while making every result grow with the number of groups. Building `ma…
    osv-scannerCVE-2026-14257
  • sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591
    ### Impact A number of vulnerabilities, two rated as "High" severity using CVSSv4, have been discovered and fixed in the upstream libvips dependency. Those processing untrusted input with versions of sharp prior to 0.35.0 are affected. ### Patches #### Using prebuilt binaries…
    osv-scanner
  • shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)
    ### Summary `shell-quote`'s `parse()` finalizes its token list with a `reduce` that uses `Array.prototype.concat` as the accumulator. Each `prev.concat(arg)` copies the entire growing array, so `parse()` runs in **O(n²)** in the number of tokens. An unauthenticated attacker who c…
    osv-scannerCVE-2026-13311
  • MD5/SHA1 is cryptographically broken for security use (integrity/signatures/ password hashing). Use SHA-256+ or a password KDF. (Apache-2.0.)
    MD5/SHA1 is cryptographically broken for security use (integrity/signatures/ password hashing). Use SHA-256+ or a password KDF. (Apache-2.0.)
    semgrepsrc/services/telemetry/backfill.ts:80
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgrepworkers/sync-hub/src/control-plane-probe.ts:49
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgrepopenclaw/test-install.sh:614
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgrepworkers/sync-hub/vitest.config.ts:258
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgrepopenclaw/install.sh:876
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgrepopenclaw/install.sh:962
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgrepopenclaw/test-install.sh:574
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgrepopenclaw/test-install.sh:585
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgrepopenclaw/test-install.sh:603
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgrepdocker/e2e/server-e2e.mjs:152
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgrepdocs/public/antigravity-cli/setup.mdx:81
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgrepdocs/public/usage/gemini-provider.mdx:71
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgrepdocs/public/usage/openrouter-provider.mdx:105
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgrepopenclaw/install.sh:40
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgrepopenclaw/install.sh:867
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgrepopenclaw/test-install.sh:1616
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgrepplugin/skills/cloud-sync/SKILL.md:59
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgrepscripts/e2e-server-docker.sh:24
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgrepscripts/e2e-server-docker.sh:150
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgrepscripts/e2e-server-docker.sh:151
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgrepscripts/e2e-server-docker.sh:168
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgrepscripts/e2e-server-docker.sh:169
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgrepscripts/sync-matrix-e2e.ts:34
  • 'RUN cd ...' to change directory
    Use WORKDIR instead of proliferating instructions like 'RUN cd … && do-something', which are hard to read, troubleshoot, and maintain.
    trivydocker/claude-mem/Dockerfile:45

This report is public.