Steve Loughran created HADOOP-15069: ---------------------------------------
Summary: support git-secrets commit hook to keep AWS secrets out of git Key: HADOOP-15069 URL: https://issues.apache.org/jira/browse/HADOOP-15069 Project: Hadoop Common Issue Type: Improvement Components: build Affects Versions: 3.0.0 Reporter: Steve Loughran Assignee: Steve Loughran Priority: Minor The latest Uber breach looks like it involved AWS keys in git repos. Nobody wants that, which is why amazon provide [git-secrets|https://github.com/awslabs/git-secrets]; a script you can use to scan a repo and its history, *and* add as an automated check. Anyone can set this up, but there are a few false positives in the scan, mostly from longs and a few all-upper-case constants. These can all be added to a .gitignore file. Also: mention git-secrets in the aws testing docs; say "use it" -- This message was sent by Atlassian JIRA (v6.4.14#64029) --------------------------------------------------------------------- To unsubscribe, e-mail: common-dev-unsubscr...@hadoop.apache.org For additional commands, e-mail: common-dev-h...@hadoop.apache.org