25 ms·
How about encryption? https://github.com/AGWA/git-crypt https://github.com/AGWA/git-crypt has been solid for me
by tln 3y ago
How about encryption?
https://github.com/AGWA/git-crypt https://github.com/AGWA/git-crypt has been solid for me
- ghusto 3y agoI like this a lot and use it myself. Always have a tough time convincing developers though, because they don't like "all that terminal stuff" :/
- shrimp_emoji 3y agoAre you sure they're developers? Nevermind, I guess they can be web developers :p
- ghusto 3y agoDidn't want to go there, but I think you get it. When your developers are using JavaScript to write backend programs, you know where the bar is.
- computerfriend 3y agoOld secrets are around forever, tied to long lived credentials (PGP keys) who's access can't be revoked (because it's always in the commit history). Additionally, it can be quite painful in an ever-changing collaborative context.
- remram 3y agoAssuming you mean encrypting the secret files specifically and not the whole repo. This could work, but why put the secrets in the repository at all? Either everyone has to replace them with their own secrets before being able to run the code. Or everyone has to have the key to decrypt the actual credentials (developers, interns, deployments, CI, scanners, etc) making it not secret. Why not inject the credentials at runtime, from a system meant for this, with support for auditing and key rotation etc?