Files Deleted From GitHub Repos Leak Valuable Secrets

Files Deleted From GitHub Repos Leak Valuable Secrets
Summary: Security researcher Sharon Brizinov uncovered hundreds of leaked secrets in deleted files from public GitHub repositories, earning ,000 in bug bounties. His findings highlight the dangers of Git’s data retention practices, where deleted files may still be accessible, posing significant security risks for developers. Brizinov emphasizes the necessity of understanding Git’s functionality and the importance of rotating keys if leaks occur.

Affected: Public GitHub repositories

Keypoints :

  • Brizinov’s automated tool scanned public repositories for deleted files and discovered numerous active secrets, including API tokens and credentials.
  • Git retains deleted files for a period, complicating the removal of sensitive information and increasing the risk of compromise.
  • Developers should avoid merely deleting secret-containing files and instead rotate those secrets to mitigate potential breaches.

Source: https://www.securityweek.com/files-deleted-from-github-repos-leak-valuable-secrets/