covid-19-jurnal-medical icon indicating copy to clipboard operation
covid-19-jurnal-medical copied to clipboard

Credentials are stored on GIT repository

Open RaduCStefanescu opened this issue 4 years ago • 2 comments

An attacker or a malicious administrative user with access to the GIT platform or the GIT repository can obtain or create a public leak of a wide range of credentials and other API keys in order to create disturbances, escalate privileges or use the obtained information in other attacks.

Do not store credentials, API keys or configuration files in GIT. The most you can do is place a dummy configuration file that will be edited prior to any deployment on the system environment.

RaduCStefanescu avatar May 25 '20 10:05 RaduCStefanescu