タグ

ブックマーク / www.notgitbleed.com (1)

  • NotGitBleed - TL;DR

    NotGitBleed - TL;DR Due to configuration errors or human error, significant numbers of people may have accidentally checked GitHub credentials into GitHub commits as metadata, most commonly a username as the author name and a password in the email address field. We estimate in the region of 50,000 to 100,0001 user credentials may have been affected covering a wide range of organisations including

    everybodyelse
    everybodyelse 2022/04/13
    IDEとかでgit操作してると、うっかりメールアドレスの入力フォームにパスワード入れちゃって、気づかずgit logでパスワードがリークしたって話か。githubがそれに気づいて関連するPATの無効化とパスワードリセットをしたと
  • 1