v1.17.0 includes detection and mitigation for several new secret exposures including your github token hiding behind a simple `git` invocation.
https://t.co/2aGW7cledT
Do you know that using GitHub CLI (gh) may expose you to supply-chain attacks?
It stores a long-lived GitHub token on your machine, which can be stolen by any malicious scripts.
This is what happened in the recent Nx Console supply-chain compromise, which led to GitHub’s internal source code being leaked.
Do you know that using GitHub CLI (gh) may expose you to supply-chain attacks?
It stores a long-lived GitHub token on your machine, which can be stolen by any malicious scripts.
This is what happened in the recent Nx Console supply-chain compromise, which led to GitHub’s internal source code being leaked.
v1.7.0: faster & more robust package updates; >17,000 packages scanned for isotopic security; 99 isotopes keeping your tool secrets out of plain text.
https://t.co/Nriq8RAR0j
👋 We're Automic Vault.
Your agents are autonomous. Your secrets are in plain text. Your tools can delete prod with one command.
We fix that — at the layer that actually matters.
Built by @mxcl, creator of Homebrew.