hackforla / ops

A repository for the OPS Community of Practice
https://github.com/orgs/hackforla/projects/73
MIT License
8 stars 7 forks source link

Create a Guide/Template: Preventing Secrets & Credentials Leaks in GitHub #10

Open gregpawin opened 3 years ago

gregpawin commented 3 years ago

Overview

We need to create a guide to preventing secrets and credentials from being published on GitHub.

Action Items

Resources

Update tracker issue (TBD) with the name of item you are working

Projects with no mention of "secrets" and/or "credentials" in their Contributing.md or README.md file:

Projects to check

ExperimentsInHonesty commented 2 years ago

@salice Can you share with us:

gregpawin commented 2 years ago

When I published the Lucky Parking secrets, I got the warning within minutes and fixed it right away, which included killing the old credentials and creating new ones.

ExperimentsInHonesty commented 2 years ago

@gregpawin how long did the clean up take? https://github.com/hackforla/engineering/issues/17#issuecomment-891511226

gregpawin commented 2 years ago

It took less than 30 mins

ExperimentsInHonesty commented 2 years ago

sophias repo with pre commit hooks https://github.com/100Automations/github-actions https://github.com/100Automations/pre-commit-hooks

JasonEb commented 1 year ago

Trying to revive and keep a pulse on this issue. @gregpawin is this issue still active for you? Is there anything we can help you with?

gregpawin commented 1 year ago

Sorry, this issue originated from the engineering COP as a part of the effort to create guides for all the COPs. I have since then stepped down from lead engineering COP and it seems that the issue got moved to ops.

JasonEb commented 1 year ago

Thanks so much for the update! We'll follow-up with Bonnie and see what's to be done with this issue.

On Wed, Jul 20, 2022 at 5:48 PM Greg Pawin @.***> wrote:

Sorry, this issue originated from the engineering COP as a part of the effort to create guides for all the COPs. I have since then stepped down from lead engineering COP and it seems that the issue got moved to ops.

— Reply to this email directly, view it on GitHub https://github.com/hackforla/ops/issues/10#issuecomment-1190912670, or unsubscribe https://github.com/notifications/unsubscribe-auth/ABQCKQ7PJNTJJWJ4FZGUFLDVVCM45ANCNFSM5HKJ4X7Q . You are receiving this because you were assigned.Message ID: @.***>