Dudinha retweetledi

> you save $50k to build your project
> you hire a team that ships clean code
> you set up a private github repo
> .env in gitignore, secrets in a vault, mfa on every account, tokens rotated quarterly
> you did everything by the book
> then one github employee auto-updates a vs code extension
> 11 minutes
> 3,800 of github's internal repos walk out
in those repos:
> the tools github engineers use to access your account
> the access management code that decides who reads what
> signing keys
> scripts running prod
you did everything right and it still wasn't enough
The Smart Ape 🔥@the_smart_ape
English









