2 ms·
Really surprising to see that sensitive credentials were checked in to VCS. Apart from peer code review, how can a company avoid developers checking in sensitiv
by davidumoh 9y ago
Really surprising to see that sensitive credentials were checked in to VCS. Apart from peer code review, how can a company avoid developers checking in sensitive data to VCS?
- rplnt 9y agoYou could have a git hook (even remote) that would check for pre-configured patterns and reject the push if it contains them. Quick google yielded this https://github.com/awslabs/git-secrets https://github.com/awslabs/git-secrets
- selvakn 9y agoPlug: https://github.com/thoughtworks/talisman https://github.com/thoughtworks/talisman