maggma icon indicating copy to clipboard operation
maggma copied to clipboard

Scan for API keys on PR

Open Andrew-S-Rosen opened this issue 2 years ago • 3 comments

I saw some terrifying Twitter threads about people accidentally uploading credentials to their GitHub repo and it causing massive security/financial havoc.

Might it be worth adding https://github.com/marketplace/gitguardian to maggma since this is one of the packages where that might be done accidentally? I added it to my repos, and it took all of about 30 seconds to setup (you just hit install). It's free.

Andrew-S-Rosen avatar Jul 10 '23 16:07 Andrew-S-Rosen

Sounds like a good idea to me! It looks like it has to be activated by a GitHub org admin (which I am not). What do you think @munrojm? If you agree, can you enable?

rkingsbury avatar Jul 11 '23 21:07 rkingsbury

Here's the Twitter thread btw if you're morbidly curious: https://twitter.com/georgemporter/status/1677378445658173442

Andrew-S-Rosen avatar Jul 11 '23 22:07 Andrew-S-Rosen

Looking at it closer, it might make sense to add it to the org instead of through my personal account as it has to go through github billing despite it being free for public repos.

munrojm avatar Jul 12 '23 07:07 munrojm