Skip to main content

Coveralls Token

Description#

General#

  • Documentation: https://docs.coveralls.io/api-introduction
  • Summary: Coveralls is a developments tool that helps monitoring code coverage. Results of tests and source code can be sent via an API using a dedicated token. This detector aims at catching those tokens.
  • IPs allowlist: This feature is not mentioned in the documentation.
  • Scopes: All tokens have the same permissions.

Revoke the secret#

Tokens can be deleted or created from the user's account page.

Check for suspicious activity#

The web application shows a last used date for each token.

Details for Coveralls token#

  • Category: Development tool

  • Company: Coveralls

  • High recall: False

  • Validity check available: True

  • Only valid secrets raise an alert: True

  • Minimum number of matches: 1

  • Occurrences found for one million commits: very rare

  • Prefixed: False

  • PreValidators:

- type: FilenameBanlistPreValidator  banlist_extensions:  - css  - html  - lock  - md  - storyboard  - xib  banlist_filenames: []  check_binaries: false- type: FilenameBanlistPreValidator  banlist_extensions:  - ipynb  banlist_filenames: []  check_binaries: false- type: ContentWhitelistPreValidator  patterns:  - coveralls

Examples#

- text: >    coveralls_repo_token=QEAuo5Pufwd2TGqQiqt3a1HWWp3i9mRTF  apikey: QEAuo5Pufwd2TGqQiqt3a1HWWp3i9mRTF