When used to pull source code from a private repository using a Personal Access Token (PAT), some versions of dbt-core write a URL with the PAT in plaintext to the package-lock.yml file.
The bug has been fixed in dbt-core v1.7.3.
Remove any git URLs with plaintext secrets from package-lock.yml file(s) on servers, workstations, or in source control. Rotate any tokens that have been written to version-controlled files.
{
"cwe_ids": [
"CWE-315"
],
"github_reviewed": true,
"github_reviewed_at": "2023-12-08T15:38:37Z",
"nvd_published_at": null,
"severity": "LOW"
}