Hacker Newsnew | past | comments | ask | show | jobs | submit | aghlabid00x0's commentslogin

Forest Admin's out-of-the-box admin panel + the convenience of the cloud, this is all developers ever wanted for their internal tools!


To Casablanca, Morocco.


Hey, maybe try running a GitGuardian [1] scan on all those repositories to look for hardcoded secrets. GitGuardian can also test in some cases if the secrets are valid or not, meaning you have to revoke and rotate them asap. I hope this helps.

[1] https://www.gitguardian.com/monitor-internal-repositories-fo...

Disclaimer: I work for GitGuardian.


geez.


Louise


You are literally asking why we don't say what is literally true and instead we say something that elicits an image by comparison.

That's the answer. Because they choose to use a metaphor instead of speaking literally.


“dark matter” sounds like marketing speak.


well, they haven’t turned my building’s heating on yet.


Here's a checklist [1] (again, from gitguardian) of steps to follow before open-sourcing projects and [2] a guide on how to remediate hardcoded/exposed secrets.

[1] https://blog.gitguardian.com/safely-open-source-software-bes... [2] https://blog.gitguardian.com/leaking-secrets-on-github-what-...


Great idea, but hard to enforce. Just use a scanning CLI like TruffleHog, Gitleaks, or ggshield from GitGuardian to catch all sorts of hardcoded secrets.


GitGuardian actually does this, it monitors an extended perimeter of devs and their personal/open-source repos for corporate secrets or keywords – https://www.gitguardian.com/monitor-public-github-for-secret...


Yeah, because as an employee what I totally want is my employer to monitor my every digital move outside of work!


Make a private repo. I wouldn't blame a corp if they tried to scan every public github repo for their API keys, let alone an employee's public account.


In the meantime, try ggshield cli https://github.com/GitGuardian/ggshield


Nah thanks, I'm already running Trufflehog for free on all of our multiple orgs' thousands of repos.

I think we would consider GG if its pricing was acceptable for non-profits though.


FYI - GitGuardian is free for individuals and teams smaller than 25


As told earlier, we have thousands of repos. And our teams are thousands of users on GH.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: