4 ms·
> There are always creds in private/company repos! Lots. I disagree with the "always" in this statement. Sloppy, lazy private repos sure. It is possible to hav
by chunk_waffle 4y ago
> There are always creds in private/company repos! Lots.
I disagree with the "always" in this statement. Sloppy, lazy private repos sure. It is possible to have them completely absent in any and all repos though I've only seen and been part of such an effort once, it takes a lot of work to make sure it happens and I have little faith in most companies following through with that.
- TechBro8615 4y agoIn my experience it's a pretty low bar to keep private credentials outside of source code. If a "security" company like Okta has secrets in their source code, that's embarrassing and unexpected. Any competent team of 2+ developers should be able to avoid this. However, what's more common is secrets in CI variables. If their GitHub was breached, they should be more concerned with whether the attackers had access to GitHub Actions logs or secrets.