Skip to content

Git History Secret Scan

git-history-secret-scan is a critical severity check in the devops category, written in go. Its source is templates/devops/git/git-history-secret-scan.go in cert-x-gen-templates.

Detects exposed .git directories on web servers that allow reconstruction of repository history and extraction of credentials, API keys, tokens, and other secrets from commit history and configuration files.

Field Value
Id git-history-secret-scan
Severity critical
Language go
Category devops
Author BugB Technologies
Template version not recorded
Confidence 95
CVSS not recorded
Weakness CWE-312
Tags git, secret-exposure, credential-leak, misconfiguration, source-code-disclosure, devops
Target kind not recorded
Oracle not recorded

Declared in the header. cxg parses @references and then discards it, and nothing at scan time reads it, so this is the only place the links a template cites are surfaced.

To see what the copy on your machine says about itself, and to confirm it is installed at all:

Terminal window
cxg template info git-history-secret-scan

The id it prints is the one to pass anywhere a template is selected. See cxg template for the rest of the subcommand, Scan a target for running a scan, and A match is not a finding for how to read what comes back.