4 ms·
Looks like a good opportunity for an open source tool that scans a git repository for interesting/private information. Obviously it could be used for nefarious
by jaryd 12y ago
Looks like a good opportunity for an open source tool that scans a git repository for interesting/private information. Obviously it could be used for nefarious purposes, but it would be helpful for anyone looking to open source an existing repo.
Another alternative is to store credentials in environment variables :)
- moot 12y ago> Looks like a good opportunity for an open source tool that scans a git repository for interesting/private information. These already exist in droves, which is exactly how our Amazon credentials were found. http://www.itnews.com.au/News/375785,aws-urges-developers-to-scrub-github-of-secret-keys.aspx http://www.itnews.com.au/News/375785,aws-urges-developers-to...
- jdhendrickson 12y agoI wasn't cognizant of the need to include a step in which you scan your own repo, just as a fail safe. So thanks for posting this.
- ufmace 12y agoProbably a good practice. For my current project, I've been careful to never commit any API credentials or other secrets to the repo, even though I don't currently have any intention of making it public. It's harder to know what you're missing, though.
- yeukhon 12y agoTime for this question to come back live. http://security.stackexchange.com/questions/56911/does-anyone-know-the-website-that-checks-passwords-committed-in-public-source-co http://security.stackexchange.com/questions/56911/does-anyon... Anyone has any idea about this website I am trying to find?