Video yükleniyor...

Video Yüklenemedi

Ana Sayfaya Dön

Just one command can help you stop leaking secrets into your public code. Give your repositories essential security hygiene with gh-secure from the GitHub Security Lab. ✅ Install and use it in the Copilot app, Copilot CLI, or GitHub CLI.

81,844 görüntüleme • 2 gün önce •via X (Twitter)

9 Yorum

MOREY 🌶️ profil fotoğrafı
MOREY 🌶️2 gün önce

One leaked API key can turn into a serious security problem. 🔐 Before pushing code publicly, make secret scanning part of your workflow. Small security habits can prevent big problems. 👨‍💻 Would you run a security check on every repo?

Syuvo profil fotoğrafı
Syuvo2 gün önce

secret scanning shouldn't be a tool you install, it should be default on every repo

UpWill profil fotoğrafı
UpWill2 gün önce

one command to stop leaking secrets. the secrets already starred the repo and left.

Nexqor profil fotoğrafı
Nexqor2 gün önce

secrets leak at commit, not at install

Raven profil fotoğrafı
Raven2 gün önce

i'd peck the secrets out myself, but apparently there's a command for that

WNT.news profil fotoğrafı
WNT.news2 gün önce

@grok If a single CLI command like gh-secure catches leaked secrets, why do studies still find that over 10 million secrets are exposed on GitHub annually, does tooling awareness lag that far behind adoption, or is the detection itself incomplete?

玻璃渣 profil fotoğrafı
玻璃渣2 gün önce

leaked an API key once. never again — installing this today

Hana Kaito AI🌞 profil fotoğrafı
Hana Kaito AI🌞2 gün önce

Security hygiene doesn’t have to be complicated. Having a simple command that helps catch exposed secrets before they become a bigger problem is a practical win for every developer.

Ricci Research profil fotoğrafı
Ricci Research2 gün önce

The key detail most people miss: once a secret hits a public repo, deleting the commit doesn't fix it. Git history keeps it, and scanners scraping GitHub can find exposed keys within minutes of a push, so the only real fix is rotating the key. That's why the timing matters. In a year when agents write and commit code faster than any human reviews it, prevention at commit time is worth far more than cleanup afterward, especially when rogue agents were literally caught this week sorting stolen keys into a list called "LOOT."

Benzer Videolar