GitGuardian:2021年开发机密信息泄露态势报告(英文版)(23页).pdf

编号:132512 PDF  PPTX  中文版 23页 1.83MB 下载积分:VIP专享
下载报告请您先登录!

GitGuardian:2021年开发机密信息泄露态势报告(英文版)(23页).pdf

1、The state of Secrets Sprawl on GitHubHOW LEAKY CAN IT GITGITGUARDIAN STATE OF SECRETS SPRAWL ON GITHUB2SummarySecrets Sprawl 4Findings 7Where leaks come from 10Why 11What type of secrets do we find 12File extensions that cause data breaches 13Pro bono alerting 16What happens after a leak 17Recommend

2、ations 20To conclude 21GITGUARDIAN STATE OF SECRETS SPRAWL ON GITHUB3GitHub is more than ever“The Place to Be”for developers when it comes to innovating,collaborating and networking.This amazing“octoverse”gathers more than 50 million developers working on their personal and/or professional projects.

3、So when 60 million repositories are created in a year and nearly 2 billion contributions*are added,some mistakes can happen,such as leaked secrets,Intellectual Property or PII.Some companies may think:I dont really care about public GitHub,we are not open sourcing our code,everything is stored on ou

4、r private repositories.But what about the developers of these companies they most likely have open source repositories and can leak secrets.*State of the octoverse 2020GITGUARDIAN STATE OF SECRETS SPRAWL ON GITHUB4Lets now focus on secrets.You would say that secrets stored in internal Version Contro

5、l Systems is a very bad practice but in fact it is much more frequent than you would think.But why is that?API keys,database connection strings,private keys,certificates,usernames and passwords As organizations move to cloud architectures,SaaS platforms and microservices,developers handle increasing

6、 amounts of sensitive information,more than ever before.To add to that,companies are pushing for shorter release cycles,developers have many technologies to master,and the complexity of enforcing good security practices increases with the size of the organization,the number of repositories,the numbe

友情提示

1、下载报告失败解决办法
2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
4、本站报告下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。

本文(GitGuardian:2021年开发机密信息泄露态势报告(英文版)(23页).pdf)为本站 (Kelly Street) 主动上传,三个皮匠报告文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知三个皮匠报告文库(点击联系客服),我们立即给予删除!

温馨提示:如果因为网速或其他原因下载失败请重新下载,重复下载不扣分。
客服
商务合作
小程序
服务号
折叠