Aias00 opened a new issue, #2322: URL: https://github.com/apache/rocketmq-dashboard/issues/2322
## Finding The shipped configuration includes a known administrator credential and exposes all Actuator endpoints. ## Scope Remove default credentials from tracked configuration, source them from deployment secrets, and expose only the required Actuator endpoints. ## Acceptance criteria - No usable default administrator credential is committed. - Production configuration requires an externally supplied secret. - Actuator exposure is allowlisted and verified by tests/documentation. Source: security review of current `master`. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
