Launch HN: Datree (YC W20) – Best practices and security policies on each commit https://ift.tt/3cJCp13
Launch HN: Datree (YC W20) – Best practices and security policies on each commit We are Shimon and Eyar, co-founders of Datree ( https://www.datree.io ). We've built software to help engineering teams automate the adoption of development best practices, coding standards, and security policies. When I (Shimon) was the manager of a 400-developer company's infrastructure engineering team, we had an issue where a developer committed AWS secret keys into a public GitHub repo. We were very, very lucky that the bad actors who quickly got ahold of the keys "only" spun up compute instances to mine bitcoin. Mistakes happen and they happen to the best of us. No developer wants to make mistakes, especially ones impacting production. Those mistakes can be not only costly to the business, but emotionally painful for the developer. After finding out about the issue, I had to search for any other leaked secret in our repositories to make sure we were no longer exposed. The next thing...
Comments
Post a Comment