371
Seriously how many times does this have to happen
(lemmy.world)
Welcome to Programmer Humor!
This is a place where you can post jokes, memes, humor, etc. related to programming!
For sharing awful code theres also Programming Horror.
That approach seems useful but it wouldn't have prevented the PyPI incident OP links to: the access token was temporarily entered in a
.py
python source file, but it was not committed to git. The leak was via.pyc
compiled python files which made it into a published docker build.Yeah, but a combination of this approach, and adding all compiled file types including .pyc to .gitignore would fix it.
But in this case they didn't accidentally put the token in git; the place where they forgot to put
*.pyc
was.dockerignore
.