Skip to content

Jira project names are exposed in the comments  #880

Open
@run-crash-run

Description

@run-crash-run

Describe the bug
In comments throughout the codebase there are references to Jira tickets.
Could potentially make it easier for someone to craft a phishing email.

Examples that are referenced:
SEARCHQUAL-8907
CX-2024
SD-14439
SEARCH-7329
APPSEC-2303

To Reproduce
Steps to reproduce the behavior:

  1. Click into the github search tool in the top left
  2. Search for any of the tickets above
  3. Observe the result

Expected behavior
Ideally the internal project names would not be exposed

Additional context
Possibly you should manually evaluate the comments as they might not get read by your analysis tools

Metadata

Metadata

Assignees

No one assigned

    Labels

    code qualityTypos, lint errors, style issues

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions