Looks like you committed a .env file previously with some semi-private details contained within it, plus you’ve hardcoded some Cloudinary API credentials. You may want to rotate them before they’re abused by someone. Edit: oh and some database credentials & getstream.io api credentials
Show HN: I built an open source event-management system
11–20 of 32 posts
Re: Show HN: I built an open source event-management system
#12Looks like you committed a .env file previously with some semi-private details contained within it, plus you’ve hardcoded some Cloudinary API credentials. You may want to rotate them before they’re abused by someone. Edit: oh and some database credentials & getstream.io api credentials
Thank you for this. I will do that ASAP
Feel free to contact our support or myself directly - dwight@getstream.io - if you need a hand.
Re: Show HN: I built an open source event-management system
#13Earlier quoted context omitted.
Thank you for this. I will do that ASAP
Just a heads up (since I work at getstream.io) that you can easily and quickly rotate the Stream app key/secret via the dashboard. Feel free to contact our support or myself directly - dwight@getstream.io - if you need a hand.
Re: Show HN: I built an open source event-management system
#14Earlier quoted context omitted.
Just a heads up (since I work at getstream.io) that you can easily and quickly rotate the Stream app key/secret via the dashboard. Feel free to contact our support or myself directly - dwight@getstream.io - if you need a hand.
Do you have no process ready to rotate a user's exposed credentials? It's what I would expect from any service provider once they become aware of an exposure.
Re: Show HN: I built an open source event-management system
#15Looks like you committed a .env file previously with some semi-private details contained within it, plus you’ve hardcoded some Cloudinary API credentials. You may want to rotate them before they’re abused by someone. Edit: oh and some database credentials & getstream.io api credentials
edit: ci version here - https://github.com/zricethezav/gitleaks-ci. work in progress, trying to add readme and instructions tonight. Also if anyone is interested in making gitleaks-ci into a paid github app... hmu
Re: Show HN: I built an open source event-management system
#16Re: Show HN: I built an open source event-management system
#17Earlier quoted context omitted.
Do you have no process ready to rotate a user's exposed credentials? It's what I would expect from any service provider once they become aware of an exposure.
Isn't this exactly what he explained? The user has a easy toggle on their dashboard to rotate credentials - and if he needs a hand with it, contact their support for some help.
E.g. I remember reading that Amazon even scans Github for AWS credentials proactively now, since this happened all the time.
Re: Show HN: I built an open source event-management system
#18Re: Show HN: I built an open source event-management system
#19Looks good; Needs refined UI
This way, if you're ultimately only interested in the service you're not dragging around the UI stuff (even if you're not using it).
Maybe?
Re: Show HN: I built an open source event-management system
#20Edit your profile.
Upload a non-image file.
Enjoy the backtrace.
(Only discovered because uploading an image seems to be mandatory..)