5 ms·
And this would be a cool feature from github too. A link mentioning "we found something in your code that looks like a secret, please know people will use it."
by _pctq 10y ago
And this would be a cool feature from github too. A link mentioning "we found something in your code that looks like a secret, please know people will use it."
- Klathmon 10y agoThey do this for all of their own API keys already. They not only notify you but instantly invalidate a key pushed to a public repo. Annoyingly there is no way to turn it off even when you explicitly want to share an API key knowingly. But i'm more than fine with needing to "obfuscate" an API key or manage secrets correctly knowing it saves TONS of people.
- chimeracoder 10y agoWhy would you ever want to share a valid Github API key publicly?
- remmelt 10y agoContinuous development, e.g. Jenkins? (Please don’t do this)
- Klathmon 10y agoIt's been a while, but IIRC it was a key with no permissions used on a CI server to get around github's API usage limits. It probably wasn't the best idea, but it was the only "secret" needed in the whole project and I didn't want to maintain a way of managing secrets in a public project for a pointless key. In the end I did just that, and looking back it was the better choice, but at the time it was annoying.
- Cyphase 10y ago"... used ... to get around github's API usage limits." I wonder why they'd want to invalidate that. :)
- TeMPOraL 10y agoSplit it to parts and concatenate it, then? $key = "BAAD" + "F00D" + "CAFE" + "BABE";
- Ajedi32 10y ago> But i'm more than fine with needing to "obfuscate" an API key or manage secrets correctly
- Vinnl 10y agoGitLab has this: https://docs.gitlab.com/ee/push_rules/push_rules.html#prevent-pushing-secrets-to-the-repository https://docs.gitlab.com/ee/push_rules/push_rules.html#preven... (enterprise edition, admittedly)