diff --git a/.github/workflows/wordlist-updater_awesome-list-of-secrets-in-environment-variables.yml b/.github/workflows/wordlist-updater_awesome-list-of-secrets-in-environment-variables.yml new file mode 100644 index 00000000..d139fcc0 --- /dev/null +++ b/.github/workflows/wordlist-updater_awesome-list-of-secrets-in-environment-variables.yml @@ -0,0 +1,30 @@ +name: Wordlist Updater - Awesome list of secrets in environment variables + +on: + schedule: + - cron: '0 0 1 * *' # once a month at midnight (thanks https://crontab.guru) + +jobs: + update_combined_words: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v2 + - name: Generate awesome-environment-variable-names.txt + run: cd Discovery/Variables && wget https://raw.githubusercontent.com/Puliczek/awesome-list-of-secrets-in-environment-variables/main/raw_list.txt -O awesome-environment-variable-names.txt + - name: Switching from HTTPS to SSH + run: git remote set-url origin git@github.com:danielmiessler/SecLists.git + - name: Check for changes + run: git status + - name: Stage changed files + run: git add Discovery/Variables/awesome-environment-variable-names.txt + - name: Configure git email and username + run: | + git config --local user.email "example@github.com" + git config --local user.name "GitHub Action" + - name: Commit changed files + run: git commit -m "[Github Action] Updated awesome-environment-variable-names.txt" + - name: Push changes # push the output folder to your repo + uses: ad-m/github-push-action@master + with: + github_token: ${{ secrets.GITHUB_TOKEN }} + force: true diff --git a/Discovery/Variables/awesome-environment-variable-names.txt b/Discovery/Variables/awesome-environment-variable-names.txt new file mode 100644 index 00000000..886ec548 --- /dev/null +++ b/Discovery/Variables/awesome-environment-variable-names.txt @@ -0,0 +1,81 @@ +AWS_ACCESS_KEY_ID +AWS_SECRET_ACCESS_KEY +AMAZON_AWS_ACCESS_KEY_ID +AMAZON_AWS_SECRET_ACCESS_KEY +ALGOLIA_API_KEY +AZURE_CLIENT_ID +AZURE_CLIENT_SECRET +AZURE_USERNAME +AZURE_PASSWORD +MSI_ENDPOINT +MSI_SECRET +binance_api +binance_secret +BITTREX_API_KEY +BITTREX_API_SECRET +CF_PASSWORD +CF_USERNAME +CODECLIMATE_REPO_TOKEN +COVERALLS_REPO_TOKEN +CIRCLE_TOKEN +DIGITALOCEAN_ACCESS_TOKEN +DOCKER_EMAIL +DOCKER_PASSWORD +DOCKER_USERNAME +DOCKERHUB_PASSWORD +FACEBOOK_APP_ID +FACEBOOK_APP_SECRET +FACEBOOK_ACCESS_TOKEN +FIREBASE_TOKEN +FOSSA_API_KEY +GH_TOKEN +GH_ENTERPRISE_TOKEN +CI_DEPLOY_PASSWORD +CI_DEPLOY_USER +GOOGLE_APPLICATION_CREDENTIALS +GOOGLE_API_KEY +CI_DEPLOY_USER +CI_DEPLOY_PASSWORD +GITLAB_USER_LOGIN +CI_JOB_JWT +CI_JOB_JWT_V2 +CI_JOB_TOKEN +HEROKU_API_KEY +HEROKU_API_USER +MAILGUN_API_KEY +MCLI_PRIVATE_API_KEY +MCLI_PUBLIC_API_KEY +NGROK_TOKEN +NGROK_AUTH_TOKEN +NPM_AUTH_TOKEN +OKTA_CLIENT_ORGURL +OKTA_CLIENT_TOKEN +OKTA_OAUTH2_CLIENTSECRET +OKTA_OAUTH2_CLIENTID +OKTA_AUTHN_GROUPID +OS_USERNAME +OS_PASSWORD +PERCY_TOKEN +POSTGRES_PASSWORD +SAUCE_ACCESS_KEY +SAUCE_USERNAME +SENTRY_AUTH_TOKEN +SLACK_TOKEN +square_access_token +square_oauth_secret +STRIPE_API_KEY +STRIPE_DEVICE_NAME +SURGE_TOKEN +SURGE_LOGIN +TWILIO_ACCOUNT_SID +CONSUMER_KEY +CONSUMER_SECRET +TRAVIS_SUDO +TRAVIS_OS_NAME +TRAVIS_SECURE_ENV_VARS +TELEGRAM_BOT_TOKEN +VAULT_TOKEN +VAULT_CLIENT_KEY +TOKEN +VULTR_ACCESS +VULTR_SECRET