371

One does not commit or compile credentials

Template

Context:

This meme was brought to you by the PyPI Director of Infrastructure who accidentally hardcoded credentials - which could have resulted in compromissing the entire core Python ecosystem.

you are viewing a single comment's thread
view the rest of the comments
[-] leonard@social.menzel.lol 4 points 3 months ago

@carrylex git should be password manager aware and refuse to commit if changes include a password

[-] carrylex@lemmy.world 9 points 3 months ago* (last edited 3 months ago)

Well from my personal PoV there are a few problems with that

  1. You can't detect all credentials reliably, they could be encoded in base64 for example
  2. I think it's kind of okay to commit credentials and configuration used for the local dev environment (and ONLY the local one). E.g. when you require some infrastructure like a database inside a container for your app. Not every dev wants to manually set a few dozen configuration entries when they quickly want to checkout and run the app
[-] bleistift2@sopuli.xyz 15 points 3 months ago

You can’t detect all credentials reliably,

Easy. You check in the password file first. Then you can check if the codebase contains any entry on the blacklist.

Wait…

[-] pfm@scribe.disroot.org 13 points 3 months ago

You were so close! The right solution is of course training an AI model that detects credentials and rejects commits that contain them!

[-] tyler@programming.dev 7 points 3 months ago

You joke, but GitHub advanced security does this and more. On top of the AI component, they check the hash of all things that look like an api key and then also check them against their integrated vendors to see if they’re non-expired. I don’t know how well it works, but they claim like a .1% false positive rate or something like that.

[-] MajorHavoc@programming.dev 6 points 3 months ago

I need one of those reminder bots, so I can share a link to an inevitable startup, six months from now, based on your humorous comment.

[-] dohpaz42@lemmy.world 10 points 3 months ago

I think it's kind of okay to commit credentials and configuration used for the local dev environment (and ONLY the local one).

No. Never.

E.g. when you require some infrastructure like a database inside a container for your app. Not every dev wants to manually set a few dozen configuration entries when they quickly want to checkout and run the app

In this situation, it would be better to write a simple script that can generate fresh and unique values for the dev.

Laziness is not an excuse.

[-] dohpaz42@lemmy.world 6 points 3 months ago

They do. But, as they say,ake it idiot-proof, and someone will make a better idiot.

[-] docAvid@midwest.social 15 points 3 months ago
[-] dohpaz42@lemmy.world 5 points 3 months ago

You’re right. I do that sometimes.

this post was submitted on 12 Jul 2024
371 points (97.4% liked)

Programmer Humor

19503 readers
1300 users here now

Welcome to Programmer Humor!

This is a place where you can post jokes, memes, humor, etc. related to programming!

For sharing awful code theres also Programming Horror.

Rules

founded 1 year ago
MODERATORS