4 ms·
So, to be clear. I need to contact Github directly to see if my source has been downloaded using compromised deploy keys?
by johnwards 13y ago
So, to be clear. I need to contact Github directly to see if my source has been downloaded using compromised deploy keys?
- cr4zy 13y agoI would. Although you can see some of that info here: https://github.com/settings/security https://github.com/settings/security Edit: There are also logs for your organization in https://github.com/organizations/<your_organization>/settings/security https://github.com/organizations/<your_organization>/setting...
- pegler 13y agoI emailed GitHub this morning around 8am EST. I received this response this afternoon. It sounds like they are doing their own audit and will contact you if they find anything unusual: > I wanted to check in with you about this incident - access to repositories on GitHub is logged and we're currently investigating the potential of unauthorized repository access allowed by the MongoHQ and CircleCI breaches. Although we don’t currently have any evidence of unauthorized access, or specific news regarding your repositories. > Last night, in coordination with CircleCI, we revoked all SSH keys and OAuth tokens added to GitHub accounts and repositories by their service. We'll be in contact again when we have a more substantial update or news about your organization's repositories.