Detection Engine Updates Version 2.133
This update introduces several critical security detectors for popular services, notably expanding OpenAI detection capabilities with new Project API Key, Admin API Key, and improved Service Account detection patterns. The addition of 1Password Service Account Token detection is equally significant, as both these services represent high-value security targets. OpenAI API keys provide access to powerful AI capabilities and could lead to substantial usage charges if compromised, while 1Password tokens could potentially expose entire password vaults containing sensitive credentials across an organization.
- New Detectors
- OpenAI Project API Key (v2) – Added support for detecting the new format of OpenAI project API keys.
- OpenAI Admin API Key – New detection capability for OpenAI admin API keys.
- Netlify Token (v2) – Introduced detection for the latest version of Netlify tokens.
- 1Password Service Account Token – New detector added to identify 1Password service account tokens.
- DeepSeek API Key – Now detecting DeepSeek API keys.
- Improved Detection
- OpenAI Service Account – Expanded pattern coverage for better identification.
- Rails Master Key – Updated detection rules to minimize false positives.
- GitHub Tokens – Improved recall and validation for GitHub authentication tokens.
- Groq API Key – Enhanced detection rules for greater accuracy.
- Artifactory Token – New checker added to improve detection effectiveness.
- Generic Passwords – Excluded secrets containing
*****
as they are likely false positives. - Dropbox Key – Detector group split into Dropbox Key and Dropbox Access Token for improved granularity.
- FCM API Key – Validity check is no longer available since the API has been removed. While we can no longer retrieve the validity status for FCM secrets, we still detect the keys.