Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

NotGitBleed shhgit support #100

Open
carolosf opened this issue Apr 13, 2022 · 0 comments
Open

NotGitBleed shhgit support #100

carolosf opened this issue Apr 13, 2022 · 0 comments

Comments

@carolosf
Copy link

Although shhgit scans file systems and git repos as far as I am aware it doesn't currently scan commit metadata for passwords.

Recently this has been published:
https://www.notgitbleed.com/

A lot of Github users of large open source projects accidentally commit their GitHub credentials even when tools such as shhgit are being used at an alarming rate.

Since this work has been published we have worked with GitHub to mitigate this on GitHub and they have built a scanning tool:
https://github.blog/changelog/2022-04-11-secret-scanning-detects-and-revokes-leaked-passwords/

It would be great to confirm that shhgit doesn't currently scan git commit metadata and to find out if this is something you can support in future.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant