HNHacker News
TopNewBestAskShowJobs

formerheroku

11 karma · joined April 15, 2022

submissionscomments
formerheroku··on Attack campaign involving stolen OAuth tokens issued to third-party integrators
Neither Heroku nor GitHub are addressing the key part of this - if Heroku's Dashboard apps were compromised, and thus access was given to connected GitHub repos for download - were the secrets in the Heroku config vars for the app also visible? That is the nightmare scenario for the affected app's owners.