LOW3.2
GHSA-j4g3-3q8x-jxqp
dbt-core's secret env vars written to package-lock.json in plaintext
Quick fix
GHSA-j4g3-3q8x-jxqp — dbt-core: upgrade to the fixed version with the command below.
pip install --upgrade 'dbt-core>=1.7.3'Details
### Impact
When used to pull source code from a private repository using a Personal Access Token (PAT), some versions of dbt-core write a URL with the PAT in plaintext to the `package-lock.yml` file.
### Patches
The bug has been fixed in [dbt-core v1.7.3](https://github.com/dbt-labs/dbt-core/releases/tag/v1.7.3).
### Mitigations
Remove any git URLs with plaintext secrets from `package-lock.yml` file(s) on servers, workstations, or in source control. Rotate any tokens that have been written to version-controlled files.
Are you affected?
Enter the version of the package you're using.