Shipped credential
A working key, token or password included in the files a package publishes.
Credentials end up in packages the ordinary way: a key pasted into a config file for a test, a debugging certificate kept beside the code, an environment file that was never excluded. Once published, a package is copied to mirrors and caches, so a leaked key has to be revoked, not deleted.
Most strings that look like credentials in packages are not: test values, documentation examples and the patterns of secret scanners themselves. Telling the two apart takes reading each one, which is why this site withholds where a match is and reads it by hand before calling it a leak.
Anybody who installs the package holds the credential, with whatever it can reach.
Removing the key from the next version and calling it fixed. Earlier versions stay published and mirrored, and the only fix is to revoke the key.
Related terms
See Shipped credential on a real listing
Every term here shows up in the catalogue next to a real result, with the findings published and the limits stated. Free to browse, no account needed.
Open the catalogue