Hacker News new | ask | show | jobs
by darthbanane 1133 days ago
For PAT ok but surely this also scans for aws credentials etc, or is it really just about PATs?
1 comments

What's worse: them being scanned and prevented or being committed into the public repository without anyone's knowledge?
Yeah I'm not saying this is not a net positive. I just don't understand why the recommendation reads like all is good as long as one amends the commit and nothing just happened.
That makes sense. I think it's just an extra step of protection, kind of like an alert that someone may have seen your ATM pin, so it's probably best to rotate it. But, your pin wasn't posted on the Internet.