node-rdkafka icon indicating copy to clipboard operation
node-rdkafka copied to clipboard

Test certificates are shipped in npm package

Open Chengxuan opened this issue 1 year ago • 0 comments

Environment Information

  • OS [e.g. Mac, Arch, Windows 10]: Mac
  • Node Version [e.g. 8.2.1]:v18.12.0
  • NPM Version [e.g. 5.4.2]: 8.19.2
  • C++ Toolchain [e.g. Visual Studio, llvm, g++]:
  • node-rdkafka version [e.g. 2.3.3]: v2.16.1

Steps to Reproduce

The following certificates from the librdkafka dependency are flagged as sensitive data during the security scan:

https://github.com/confluentinc/librdkafka/blob/master/tests/fixtures/ssl/client2.certificate.pem https://github.com/confluentinc/librdkafka/blob/master/tests/fixtures/ssl/client2.key

Were they included intentionally?

node-rdkafka Configuration Settings

Additional context

Chengxuan avatar Jul 05 '23 09:07 Chengxuan