Forest Admin's out-of-the-box admin panel + the convenience of the cloud, this is all developers ever wanted for their internal tools!
HN user
lumberjack24
@ GitGuardian
To Casablanca, Morocco.
Hey, maybe try running a GitGuardian [1] scan on all those repositories to look for hardcoded secrets. GitGuardian can also test in some cases if the secrets are valid or not, meaning you have to revoke and rotate them asap. I hope this helps.
[1] https://www.gitguardian.com/monitor-internal-repositories-fo...
Disclaimer: I work for GitGuardian.
geez.
“dark matter” sounds like marketing speak.
well, they haven’t turned my building’s heating on yet.
Here's a checklist [1] (again, from gitguardian) of steps to follow before open-sourcing projects and [2] a guide on how to remediate hardcoded/exposed secrets.
[1] https://blog.gitguardian.com/safely-open-source-software-bes... [2] https://blog.gitguardian.com/leaking-secrets-on-github-what-...
Great idea, but hard to enforce. Just use a scanning CLI like TruffleHog, Gitleaks, or ggshield from GitGuardian to catch all sorts of hardcoded secrets.
GitGuardian actually does this, it monitors an extended perimeter of devs and their personal/open-source repos for corporate secrets or keywords – https://www.gitguardian.com/monitor-public-github-for-secret...
In the meantime, try ggshield cli https://github.com/GitGuardian/ggshield
The access model on platforms like GitHub is flawed, a single account can be used for both professional and personal projects/repositories, leading to “fat finger” errors like this one here...
I can’t help but wonder why qursān ended up being the final form instead of qursāl.
That hardcoded secret in the powershell script really was the key to the Uber ride-hailing kingdom – https://blog.gitguardian.com/uber-breach-2022.
open to referrals?
show me the mrr
Photos don’t load on mobile :/
These folks must be retired by now and they have lived enough to find out they lost their crusade against computers.
Try https://www.specifyapp.com and thank me later!
Just like shrimps are sea cockroaches.
I’m 28 y.o and this is the first time I hear about garlic in a jar. U.S.A never ceases to amaze me.
My brother in Christ, you have an email job and you definitely don't need this browser.
A few days before this attack campaign started, I wrote a guide to help security and engineering teams prioritize and remediate thousands of secrets-in-code incidents.
Hope it can help some of the organizations dealing with this right now!
https://blog.gitguardian.com/a-practical-guide-to-prioritize...
A few days before this attack campaign started, I wrote a guide to help security and engineering teams prioritize and remediate thousands of secrets-in-code incidents.
Hope it can help some of the organizations dealing with this right now!
https://blog.gitguardian.com/a-practical-guide-to-prioritize...
The other day I wrote a guide to help security and engineering teams prioritize and remediate thousands of such incidents. Hope it helps!
https://blog.gitguardian.com/a-practical-guide-to-prioritize...
If you're looking to add secrets management and scanning to the curriculum, take a look at GitGuardian–https://www.gitguardian.com/monitor-internal-repositories-fo....
While hunting for secrets on the Docker Hub, we found that Codecov is not the only organisation to have hardcoded secrets in their Docker images.
Try GitGuardian to monitor internal repos on GitHub, 100k+ developers use it to scan their commits for all sorts of credentials and secrets.
Hardening the DevOps pipeline with automated secrets detection just got easier. You can now connect your GitHub repos to GitGuardian in a few clicks and avoid credentials leaks.
Manara sounds like a beacon of light for the MENA engineers!
Congrats to you Laila and Iliana for the launch and I will definitely be sharing this with fellow Tunisian developers :)
Forest Admin, if we're talking about more than dashboards/charts and you need to dig record deep to perform CRUD operations - https://www.forestadmin.com