The worst case of this I heard was a crypto developer that lost 300k$ of clients money when he accidentally pushed some crypto keys to GitHub public repository. Last I heard he was getting sued.
Reminds me of the time I forgot to lock the Ansible vault before pushing my new playbook to production. Thankfully my boss caught it and was able to scrub the commit, but I still got a very, very stern talking-to.
20 Comments
words_number@programming.dev · 37 pts · 3y
GitHub pushed API keys to GitHub themself once, so you're not alone xD
Dirk@lemmy.ml · 14 pts · 3y
Wasn’t this the reason they built the system to protect you from this by defining secrets not to be pushed?
StudioLE@programming.dev · 13 pts · 3y
Is this like when Facebook suggested you upload all your nudes so they can tell you if your sensitive photos are ever leaked.
dill@lemmy.one · 23 pts · 3y
Non prod creds, right? Right...
Kealper@lemmy.world · 20 pts · 3y
Narrator: It was the prod creds.
frankivo@feddit.nl · 12 pts · 3y
RangerHere@programming.dev · 9 pts · 3y
The worst case of this I heard was a crypto developer that lost 300k$ of clients money when he accidentally pushed some crypto keys to GitHub public repository. Last I heard he was getting sued.
Kettlepants@lemm.ee · 5 pts · 3y
Image not visible, link missing when opening thread.
I know it's not you, it's me. But yeah. No idea what the image is, can't copy paste from home thread.
flashgnash@lemm.ee · 10 pts · 3y
Bart Simpson writing "I will not push API keys to github" on the blackboard over and over
null@slrpnk.net · 5 pts · 3y
API*
flashgnash@lemm.ee · 2 pts · 3y
Yep, edited my comment already it is midnight in my defense
darkwing_duck@sh.itjust.works · 2 pts · 3y
Edit didn't take.
XpeeN@sopuli.xyz · 1 pts · 3y
But....It still says APT
Kettlepants@lemm.ee · 3 pts · 3y
Thank you kind person. Funnily enough the image is now visible.
thiccdiccnicc@sh.itjust.works · 4 pts · 3y
Did this for the first time yesterday 😅
And of course I had an instant watcher on my repo yet I never had one before, lol
GlitchSir@lemmy.world · 3 pts · 3y
Ooof!
eltimablo@kbin.social · 2 pts · 3y
Reminds me of the time I forgot to lock the Ansible vault before pushing my new playbook to production. Thankfully my boss caught it and was able to scrub the commit, but I still got a very, very stern talking-to.