starlightprivate / flash2

nodejs app
0 stars 0 forks source link

Check access to codeship #155

Open vodolaz095 opened 7 years ago

vodolaz095 commented 7 years ago

Currently, only devops team need to have access to codeship CI system.

How it can be dangerous?

Attacker can oversee any tokens or logs of build. Attacker can delete project? Attacker can change build type from docker powered to basic - and deploy ruined.

melvynkim commented 7 years ago

@larbyamirouche

Can you give us a complete list of our Devops people who should have an access to? Currently, at Slack#devops, there are 9 people involved with the discussions. Should I grant the permissions to all members under this channel?

solarvm commented 7 years ago

@melvynkim was it you who removed my access from codeship? :)

luckyluke317 commented 7 years ago

Shahmeer can decide this