Dad On Retire
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Email Whitelisting
  • Economy
  • Editor’s Pick
  • Investing
  • Stock
No Result
View All Result
  • Economy
  • Editor’s Pick
  • Investing
  • Stock
No Result
View All Result
Dad On Retire
No Result
View All Result
Home Editor's Pick

Travis CI flaw exposed secrets of thousands of open source projects

by
September 14, 2021
in Editor's Pick
0
0
SHARES
2
VIEWS
Share on FacebookShare on Twitter

Enlarge (credit: Getty Images)

A security flaw in Travis CI potentially exposed the secrets of thousands of open source projects that rely on the hosted continuous integration service. Travis CI is a software-testing solution used by over 900,000 open source projects and 600,000 users. A vulnerability in the tool made it possible for secure environment variables—signing keys, access credentials, and API tokens of all public open source projects—to be exfiltrated.

Worse, the dev community is upset about the poor handling of the vulnerability disclosure process and the brief “security bulletin” it had to force out of Travis.

Environment variables injected into pull request builds

Travis CI is a popular software-testing tool due to its seamless integration with GitHub and Bitbucket. As the makers of the tool explain:

Read 18 remaining paragraphs | Comments

Previous Post

Apple patches “FORCEDENTRY” zero-day exploited by Pegasus spyware

Next Post

Microsoft accounts can go passwordless, making “password123” a thing of the past

Next Post

Microsoft accounts can go passwordless, making “password123” a thing of the past

Get the daily email that makes reading the news actually enjoyable. Stay informed and entertained, for free.
Your information is secure and your privacy is protected. By opting in you agree to receive emails from us. Remember that you can opt-out any time, we hate spam too!
  • Trending
  • Comments
  • Latest

VPN servers seized by Ukrainian authorities weren’t encrypted

July 26, 2021

With help from Google, impersonated Brave.com website pushes malware

July 31, 2021

Prebiotics consumption expands in food and beverage applications – key nutritional benefits drive the ingredient demand

June 11, 2021

With help from Google, impersonated Brave.com website pushes malware

July 31, 2021

The 40 Weirdest (And Best) Charts We Made In This Long, Strange Year

0

How U.S. Government Paper Currency Began, and How Private Banknotes Ended

0

Covid Inside Rural India

0

Reply to “Reply to Whitehead” by Desvousges, Mathews and Train: (4) My treatment of the weighted WTP is biased in favor of the DMT (2015) result/conclusion

0
Harvard journal accepts left-wing paper accusing fossil fuel industry of homicide

Harvard journal accepts left-wing paper accusing fossil fuel industry of homicide

March 23, 2023
Democrat blocks GOP bill to end Biden’s vaccine requirement for non-US travelers

Democrat blocks GOP bill to end Biden’s vaccine requirement for non-US travelers

March 23, 2023
Pressure builds on Mexican government following military’s seizure of US company’s property: ‘Unacceptable’

Pressure builds on Mexican government following military’s seizure of US company’s property: ‘Unacceptable’

March 23, 2023
US says China has no reason to step up aggressive activity due to Taiwan’s stopovers in the US

US says China has no reason to step up aggressive activity due to Taiwan’s stopovers in the US

March 23, 2023

Recent News

Harvard journal accepts left-wing paper accusing fossil fuel industry of homicide

Harvard journal accepts left-wing paper accusing fossil fuel industry of homicide

March 23, 2023
Democrat blocks GOP bill to end Biden’s vaccine requirement for non-US travelers

Democrat blocks GOP bill to end Biden’s vaccine requirement for non-US travelers

March 23, 2023
Pressure builds on Mexican government following military’s seizure of US company’s property: ‘Unacceptable’

Pressure builds on Mexican government following military’s seizure of US company’s property: ‘Unacceptable’

March 23, 2023
US says China has no reason to step up aggressive activity due to Taiwan’s stopovers in the US

US says China has no reason to step up aggressive activity due to Taiwan’s stopovers in the US

March 23, 2023

Disclaimer: DadOnRetire.com, its managers, its employees, and assigns (collectively "The Company") do not make any guarantee or warranty about what is advertised above. Information provided by this website is for research purposes only and should not be considered as personalized financial advice. The Company is not affiliated with, nor does it receive compensation from, any specific security. The Company is not registered or licensed by any governing body in any jurisdiction to give investing advice or provide investment recommendation. Any investments recommended here should be taken into consideration only after consulting with your investment advisor and after reviewing the prospectus or financial statements of the company.

  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Email Whitelisting

Copyright © 2022 DadOnRetire. All Rights Reserved.

No Result
View All Result
  • Economy
  • Editor’s Pick
  • Investing
  • Stock

Copyright © 2022 DadOnRetire. All Rights Reserved.