|
|
|
|
|
by toomuchtodo
442 days ago
|
|
Perfect security does not exist. Their security system (people, tech) operated as expected with an impressive response time. Room for improvement, certainly, but there always is. Edit: Success is not the absence of vulnerability, but introduction, detection, and response trends. (Github enterprise comes out of my budget and I am responsible for appsec training and code IR, thoughts and opinions always my own) |
|
Having your CI/CD pipeline and your git repository service be so tightly bound creates security implications that do not need to exist.
Further half the point of physical security is tamper evidence. Something entirely lost here.