Earlier quoted context omitted.
That's basically the only paragraph of new information in the whole... well, let's call it what it is, a press release basically. It is a thing to know. That they had a token checked into source code that probably shouldn't have been, and that the attacker somehow got access to the source code in a private github repo. * yeah, we still don't know how. Which is kind of important. But figuring out how they got access t…
> is to some extent back on github How is it on Github? We know that it was a third-party integration that compromised. Almost every single third-party integration needs the ability to read source code. The fault here lies on Heroku for storing secrets that allowed access to their main customer database in a source code repo that was accessible to a third-party provider, as well as with the third party provider (what…
The whole sentence I wrote was: "But figuring out how they got access to a private github repo is to some extent back on github, at least potentially..."
> …That feels like a failure of logging on Github's part, without any additional information.
There you go, you answered your own question too.