Travis Personal Token

Bridgecrew Policy ID: BC_GIT_69
Chekov Check ID: CKV_SECRET_69
Severity: LOW

Travis Personal Token


Travis CI is a hosted CI service used to build and test software projects hosted on GitHub and Bitbucket. Travis CI was the first CI service which provided services to open-source projects for free and continues to do so. TravisPro provides custom deployments of a proprietary version on the customer's own hardware.

Fix - Buildtime

Travis CI

Step 1: Revoke the token

  1. Go to Travis CI and click on your avatar, then click on Settings
  2. Click on the Tokens tab
  3. Find the compromised token and click on the trash icon

Step 2: Monitor for abuse