4 ms·
That's the first thing that triggered me as well. The only thing that 3rd party JS will have access to is everything on the page. Now, the things on the page
by avitzurel 9y ago
That's the first thing that triggered me as well.
The only thing that 3rd party JS will have access to is everything on the page.
Now, the things on the page are sensitive (the secrets from the env variables are dumped in the UI).
Secrets in the secrets page are not exposed at any time, even when you go to edit. Only in the build screen, it's exposed to the output.
Those 3rd party libs DO NOT have access to your source code at any time. The only time they will have access to your code is if they gain SSH access to the machines that are running the build. And that's not trivial.
Even if your public key is exposed, they don't have access to checkout github with that.
So yeah, it's 3rd party libs in a "private" context but not more than that IMHO.
- detaro 9y agoFrom searching for discussions around CircleCI API and cookies it seems like at least some API endpoints might accept session cookies for authentication. I guess we'll have to wait for a CircleCI statement to address this in detail (or someone testing it).