4 ms·
Looks like it's addressed in an update to https://status.heroku.com/incidents/2413 https://status.heroku.com/incidents/2413 The compromised tokens could provid
by fdr 4y ago
Looks like it's addressed in an update to https://status.heroku.com/incidents/2413 https://status.heroku.com/incidents/2413
The compromised tokens could provide the threat actor access to customer GitHub repos, but not customer Heroku accounts
While the situation can get worse, this token alone may not be enough...
- throwaway__thr 4y agoThe token isn’t nearly as concerning as what it implies: this stolen token would have been stored in heroku’s DB. However it got out likely has broader implications.