I wish more apps supported this.
Also on my list is a "Don't ever let me disable 2FA" setting. I'm more worried about malicoius resets than I am about ever losing my 2FA device and backup codes.
> Add an option to delete old logs. If you have ever dumped env vars to the log file, an attacker can export these.
I surprised that secrets make it into the logs at all. I would have expected them to filter anything that's in an env secret from the log output. Pretty sure Travis does this.
> Enable subresource integrity, or serve JS from each of these companies from the CircleCI domain.
That's not much of an option for this type of thing as the third parties would then have a PITA time dealing with upgrades (so they wouldn't support it). Using <script src="hxxps://tracker.example.com/path/to/script.js"></script> (rather than a fixed version) allows for live upgrades as they're in control of the resource that is loaded.
And you can't load the script from your domain as at the end of the day it's got to get instructions and upload data to the third party. At best you'd be loading a shim that does the same thing as the script tag.