Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Do you deploy confidential information into the repo ? That would be the root problem.


Things don't have to be confidential to be an issue. Leaking the actual maintainer's names (as opposed to the Drupal list), for instance, would not necessarily be considered confidential, but still an issue if it showed up.


Usually passwords or keys are stored in a config file, and that is stored in a place outside the repo.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: