Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Email, bleh, I'm sure I'm not the only one who basically /dev/null's emails from github about pearl-clutching "security" but I wanted to point out that for quite a few providers they actually have an integration to revoke them if found in a public repo, which I think is way more handy

https://docs.github.com/en/code-security/secret-scanning/sec...

and the list is way bigger than I recalled: https://docs.github.com/en/code-security/secret-scanning/int...



You can turn those GitHub security warnings off if you don't want them.

>quite a few providers they actually have an integration to revoke them if found in a public repo, which I think is way more handy

Yes I've also gotten an email from Amazon saying they revoked a key someone inadvertently leaked (but so long ago I only remember that it happened). I read my AWS emails at least.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: