3 ms·
Best practice when releasing source code generally is making sure no one left API keys, etc. in source code. (Obviously you never check secrets in in the first
by truthsocial 2y ago
Best practice when releasing source code generally is making sure no one left API keys, etc. in source code. (Obviously you never check secrets in in the first place, keeping them separate, but it's still worth automated and manual review before releasing.)
- buildbot 2y agoThat's not IP, that's secrets. IP needs to be included.
- davorak 2y agoLogos, art, and similar? I would have guessed that would not need to be included.
- h0l0cube 2y agoThose would be provided by a CDN, with some storage service underneath that. Configuration secrets that (transitively) point to these services should be injected by the build system and have no business being in source code.
- monocasa 2y agoTrade secrets are a type of IP.
- deleted 2y ago[deleted]
- h0l0cube 2y agoThey mean 'configuration secrets'. Those variables used for internal authorization and configuration that should never be leaked outside the organization. If source code of AGPL software is modified and used for an online service, it needs to be published in respecting the license, and best any 'trade secrets' are isolated. The only other alternatives are to use the code as-is or build a proprietary solution from scratch.
- monocasa 2y agoI know what they meant. My point is that the uses of the term at as disparate as they're making it. You would be sued under trade secret law if you intentionally leaked them.
- h0l0cube 2y ago> I know what they meant. If you did, "Trade secrets are a type of IP." seems to be an unrelated assertion to the thread. > You would be sued under trade secret law if you intentionally leaked them. To embed trade secrets into an open source fork, would suggest either the intent to withhold the modified source, ignorance, or flat out incompetence. Anyone, be it a lone hacker or a large organization, can simply fork the source on the platform it's hosted on (e.g., GitHub, GitLab) at a click of a button. It is a requirement of AGPL that all deployed updates to a product or online service need published source[0]. Once again, very simple to have this running off CI/CD. If there are trade secrets in that source... oh well, they have to be published too. So the simple solution is to not have them in there in the first place (i.e., abstract it away). [0] https://news.ycombinator.com/item?id=40032179 https://news.ycombinator.com/item?id=40032179
- h0l0cube 2y agoBest practice is to not have secrets in your source code. Those should be supplied by an internal service, or injected by your build pipeline at the least.