2 ms·
You can put detection in the CI/CD pipeline to prevent from getting into the repository. And in any case. Knowing the horses have run away as soon as possible i
by mackenzie-gg 6y ago
You can put detection in the CI/CD pipeline to prevent from getting into the repository. And in any case. Knowing the horses have run away as soon as possible is pretty essential in damage prevention.
What is interesting for me here is that this leak, like the Brazilian covid leak, happened because of an employees GitHub repository. Which companies have no authority over.
GitGuardian at least scans the GitHub accounts of employees though.
- ChrisMarshallNY 6y agoTrue, but I have always taken the position that security starts before we write our first line of code, and should be something that we keep front and center, every line we write. When I write a line of code, I have an automatic "red team" approach. I think "I'm a blackhat hacker. How do I leverage this line?" Not a 100% guarantee, but it sure does help the result to be more secure. In my experience, 99% of security is good old-fashioned horse sense.