3 ms·
I don't think they know yet. It's pretty plain that source code exfiltration occurred, though. It's not clear to me how exactly to confirm that the exfiltrati
by samcheng 4y ago
I don't think they know yet.
It's pretty plain that source code exfiltration occurred, though. It's not clear to me how exactly to confirm that the exfiltration happened to your account or not.
From the other thread:
> GitHub indicates they are performing an audit and if they find such evidence they will notify each account/org within the next 72 hours.
- nomilk 4y agoProbably for a lot of us, a source code leak is not the end of the world, but leaked secrets (i.e. config vars) should be addressed immediately. Rotating credentials will take time. E.g. 20 heroku apps with 30 secrets per app could realistically take several hours (even days) to fully rotate creds.
- lumberjack24 4y agoA few days before this attack campaign started, I wrote a guide to help security and engineering teams prioritize and remediate thousands of secrets-in-code incidents. Hope it can help some of the organizations dealing with this right now! https://blog.gitguardian.com/a-practical-guide-to-prioritize-and-remediate-thousands-of-secrets-leaks-incidents https://blog.gitguardian.com/a-practical-guide-to-prioritize...