Article 5PM54 Travis CI flaw exposed secrets of thousands of open source projects (ars technica)

Travis CI flaw exposed secrets of thousands of open source projects (ars technica)

by
corbet
from LWN.net on (#5PM54)
Thisars technica article describes a problem with the Traviscontinuous-integration service:

A security flaw in Travis CI potentially exposed the secrets ofthousands of open source projects that rely on the hostedcontinuous integration service. Travis CI is a software-testingsolution used by over 900,000 open source projects and 600,000users. A vulnerability in the tool made it possible for secureenvironment variables-signing keys, access credentials, and APItokens of all public open source projects-to be exfiltrated.

Any project storing secrets in this service would be well advised toreplace them.

External Content
Source RSS or Atom Feed
Feed Location http://lwn.net/headlines/rss
Feed Title LWN.net
Feed Link https://lwn.net/
Reply 0 comments