Incident Report: Inadvertent Private Repository Disclosure
1–10 of 43 posts
Re: Incident Report: Inadvertent Private Repository Disclosure
#2Re: Incident Report: Inadvertent Private Repository Disclosure
#3Re: Incident Report: Inadvertent Private Repository Disclosure
#4Re: Incident Report: Inadvertent Private Repository Disclosure
#5Re: Incident Report: Inadvertent Private Repository Disclosure
#6I approve of the handling, but this just underscores why you want self-hosted instances.
Re: Incident Report: Inadvertent Private Repository Disclosure
#7Probs to github for the disclosure. And congratulations to gitlab for probably getting a nice boost in on premise support contracts:)
I don't know that this would make you necessarily want to make both the change to self-hosting, and the change of platform.
Re: Incident Report: Inadvertent Private Repository Disclosure
#8I approve of the handling, but this just underscores why you want self-hosted instances.
Don't you mean on-premise?
Self-hosted git (through the many installable git servers or raw git) running on a correctly sized box is almost certainly the way to go
Re: Incident Report: Inadvertent Private Repository Disclosure
#9Probs to github for the disclosure. And congratulations to gitlab for probably getting a nice boost in on premise support contracts:)
Github Enterprise is on-premise too. I don't know that this would make you necessarily want to make both the change to self-hosting, and the change of platform.
Re: Incident Report: Inadvertent Private Repository Disclosure
#10One of our engineers came up with a useful script to grab all unique lines from the history of the repository and sort them according to entropy. This helps to lift any access keys or passwords which may have been committed at any point to the top.
I think this is a great example to illustrate the tough edges of security to less experienced engineers. Github will most likely never let something like this happen to you, but on the off-chance that they do it's great to be prepared. Additionally, the response from Github was very well received. No excuses, just a thorough explanation of what happened.
I also can't help but mention that we're hiring, if you'd like to work at an organization that values security and data privacy very highly. :) usebutton.com/join-us