java-hardcoded-credentials-mining
Read-only mining codemod for SonarSource rule java:S6437 — Credentials should not be hard-coded.
It scans Java source and emits metrics only; it never modifies code (return null).
Findings are high-signal review candidates surfaced by AST pattern matching — they are
not proven vulnerabilities. A static mining pass cannot prove an end-to-end taint flow
from an untrusted source to the sink, so confirm data flow before remediating.
| Field | Value |
|---|---|
| Rule key | java:S6437 |
| Type | Vulnerability |
| Severity | Blocker |
| Primary CWE | CWE-798 (Use of Hard-coded Credentials) |
| Tags | cwe |
What it detects
Credential-setting APIs invoked with a hard-coded, non-empty string literal.
Sinks:
setPassword / setUser(name) / setSecret / setSecretKey / setAccessKey / setApiKey / setCredentials / setToken / withPassword / withUsername / basicAuthentication / setBasicAuthnew PasswordAuthentication / UsernamePasswordCredentials / BasicAWSCredentials / UsernamePasswordAuthenticationToken / NTCredentials
Emission rule: Emits when a credential argument is a non-empty string literal (including "...".toCharArray()). Values from env/config method calls are skipped.
Metric: java-hardcoded-credentials-mining
| dimension | meaning |
|---|---|
rule | SonarSource rule key |
cwe | primary CWE identifier |
severity | always blocker |
sink | the detected sink (method/constructor) |
package_name | enclosing Java package |
class_name | enclosing class/interface/enum/record |
method_name | enclosing method/constructor (or <none>) |
file | file path (relative to scan target) |
line | 1-based line of the finding |
arg_kind | always literal |
Security standards
- CWE-259 (Use of Hard-coded Password)
- CWE-798 (Use of Hard-coded Credentials)
- OWASP Top 10 2021: A7
- OWASP Top 10: A2
Run locally
bash
Part of the java-security-blocker-mining suite covering 19 blocker-severity
Java vulnerability rules. Each codemod is read-only and emits a single named metric.