Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Scan for API keys on PR #821

Open
Andrew-S-Rosen opened this issue Jul 10, 2023 · 3 comments
Open

Scan for API keys on PR #821

Andrew-S-Rosen opened this issue Jul 10, 2023 · 3 comments

Comments

@Andrew-S-Rosen
Copy link
Member

Andrew-S-Rosen commented Jul 10, 2023

I saw some terrifying Twitter threads about people accidentally uploading credentials to their GitHub repo and it causing massive security/financial havoc.

Might it be worth adding https://github.com/marketplace/gitguardian to maggma since this is one of the packages where that might be done accidentally? I added it to my repos, and it took all of about 30 seconds to setup (you just hit install). It's free.

@rkingsbury
Copy link
Collaborator

Sounds like a good idea to me! It looks like it has to be activated by a GitHub org admin (which I am not). What do you think @munrojm? If you agree, can you enable?

@Andrew-S-Rosen
Copy link
Member Author

Here's the Twitter thread btw if you're morbidly curious: https://twitter.com/georgemporter/status/1677378445658173442

@munrojm
Copy link
Member

munrojm commented Jul 12, 2023

Looking at it closer, it might make sense to add it to the org instead of through my personal account as it has to go through github billing despite it being free for public repos.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants