GitHub yaita cheki yekuburitswa kwechakavanzika data mumarepositori

GitHub yakazivisa kuunzwa kwesevhisi yemahara yekutevera kuburitswa kwetsaona yedata muzvinyorwa, senge encryption kiyi, mapassword eDBMS uye maAPI ekuwana tokeni. Kare, sevhisi iyi yaingowanikwa chete kune vatori vechikamu muchirongwa chekuyedza beta, asi ikozvino chatanga kupihwa pasina zvirambidzo kune ese eruzhinji repositori. Kuti ugone kuvheneka repository yako, mune zvigadziriso muchikamu che "Code chengetedzo uye kuongorora", iwe unofanirwa kumisa iyo "Chakavanzika scanning" sarudzo.

Pakazara, anopfuura 200 matemplate akaiswa kuti aone marudzi akasiyana emakiyi, tokens, zvitupa uye zvitupa. Kutsvaga kwekuvuza kunoitwa kwete chete mukodhi, asiwo mune nyaya, tsananguro uye makomendi. Kuti ubvise zvisungo zvenhema, mhando dzechiratidzo chete dzakavimbiswa dzinotariswa, dzinofukidza anopfuura zana akasiyana masevhisi, anosanganisira Amazon Web Services, Azure, Crates.io, DigitalOcean, Google Cloud, NPM, PyPI, RubyGems uye Yandex.Cloud. Pamusoro pezvo, inotsigira kutumira zviziviso kana zvitupa nemakiyi aonekwa.

Muna Ndira, kuyedza kwakaongorora zviuru gumi nezvina zvekuchengetedza vachishandisa GitHub Zviito. Nekuda kweizvozvo, kuvapo kwedata rakavanzika kwakaonekwa mu14 repositories (1110%, i.e. anenge ese gumi nemaviri). Semuyenzaniso, 7.9 GitHub App tokens, 692 Azure Storage kiyi, 155 GitHub Personal tokens, 155 Amazon AWS makiyi, uye makumi mashanu eGoogle API makiyi akaonekwa mumatura.

Source: opennet.ru

Voeg