Can anyone confirm or rule out whether config vars for heroku apps have been exposed?
I can't see anything mentioned on the incident page nor config vars page
I can't see anything mentioned on the incident page nor config vars page
It's pretty plain that source code exfiltration occurred, though. It's not clear to me how exactly to confirm that the exfiltration happened to your account or not.
From the other thread:
> GitHub indicates they are performing an audit and if they find such evidence they will notify each account/org within the next 72 hours.
Hope it can help some of the organizations dealing with this right now!
https://blog.gitguardian.com/a-practical-guide-to-prioritize...