4 ms·
> ProTip: Don't price shop for CI runners and give some random company access to your company's source code and secret keys/tokens > I've personally used and l
by NikPuashkin 3y ago
> ProTip: Don't price shop for CI runners and give some random company access to your company's source code and secret keys/tokens
> I've personally used and liked, GitHub Actions, CircleCI
https://circleci.com/blog/january-4-2023-security-alert/ https://circleci.com/blog/january-4-2023-security-alert/
Yeah. Random company.
- wutwutwat 3y agoEven if I felt inclined to give your company my business, your attitude towards any valid criticism has made it so I would never go near your company or anything that you do in the future. You're expecting companies to trust you with the ability to literally destroy them. If you can't handle security skeptical people you picked the wrong fucking niche, buddy, you're handling their source code and secrets/tokens. Your response to me saying I trust companies that have been around for a decade and have a history of being secure was to share a post about one of them having security incidents. Got em, you dunked on me! I never said they never had any incidents, because I never would. No software is 100% secure. You missed the key part, which was the longstanding existence and the paper trail, which the thing you linked to is actually a part of, which is important. They get my business over a fly by night .cloud company being pitched by a person being defensive when people have security concerns, for a new saas, in another country, who has yet to link to any third party security audits, compliance certifications, disclosure policies, SLAs, protections, vetting/audit process, etc.
- NikPuashkin 3y agoI'm always open to discuss any security concerns, which are based on technology. However, you started here from the toxic biased comments. If my company is 3yo, I can't make it 10yo in one day, obviously, so there's no point to discuss it seriously. The age of the company is not an objective security criteria for an engineer, that's why I referred you to the CircleCI security breche. Regarding the paper work, it's to be done yet. New company can't start from applying for ISO 9002. If you would like to discuss the technical security aspects of the solution (there are many), you're welcome to my DM or to the channel in Discord.