Or maybe just have a script on local github pre-commit hook?
Or maybe just have a script on local github pre-commit hook?
I was very surprised/impressed.
Bots having tons of false positives doesn't really matter (except to the bot maker, maybe). But GitHub having tons of false positives means customers get annoyed by false alerts, locked data, whatever.
You might be right if it really is a ton, but then you work on your algorithm. I think the problem is so big that there really do need to be warnings for these kind of issues.
Also how do you differentiate an AWS root key (bad) vs an IAM Key (good)?
In my circles, at least, it's standard practice to use environment variables.
But I would think clearly it'd be an option.
Do you have articles discussing the cons of AWS keys in private repos?
We deploy our systems on vanilla EC2 instances, which are configured by using a server orchestration system (Ansible). So for any env variables to get set, we'd have to put them in config scripts, which are currently checked into github.
To make it clear, we only check in our IAM keys that are AWS service specific, like SES.