How the keys to your project leak
Almost nobody commits a password on purpose. They leak through four routes that do not look dangerous, and one of them leaves the key visible even after you delete it in the next commit.
· 4 min
3 articles
Almost nobody commits a password on purpose. They leak through four routes that do not look dangerous, and one of them leaves the key visible even after you delete it in the next commit.
You touch the sensor and you are in, without typing anything. What exactly happens between the browser and your server, why your database stops storing secrets, and the three problems nobody mentions in the announcements.
Four changes to the Dockerfile that cut the size tenfold, speed up every build and remove almost all of the attack surface. With the numbers for each step and the complete Dockerfile.