Hacker News new | ask | show | jobs
by rvz 1199 days ago
Surely you would be very comfortable to use this to 'code review' and send all your code, API keys, ENV files and secret urls to a random online service?

I don't think so.

There is a reason why large companies ban the use of unaudited third-party services like this, especially when they aren't compliant with security standards.

1 comments

ironically, said review bot will likely help you prevent checking in private API keys
Yeah haha, one more reason to use the bot and catch these mistakes