TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

CircleCI Security Incident – “Rotate any secrets stored in CircleCI”

47 点作者 dotty-超过 2 年前
Full e-mail I received https:&#x2F;&#x2F;i.imgur.com&#x2F;Nz1tEfu.png<p>https:&#x2F;&#x2F;circleci.com&#x2F;blog&#x2F;january-4-2023-security-alert&#x2F;<p>--<p>We wanted to make you aware that we are currently investigating a security incident, and that our investigation is ongoing. We will provide you updates about this incident, and our response, as they become available. At this point, we are confident that there are no unauthorized actors active in our systems; however, out of an abundance of caution, we want to ensure that all customers take certain preventative measures to protect your data as well.<p>Action request:<p>Out of an abundance of caution, we strongly recommend that all customers take the following actions:<p>- Immediately rotate any and all secrets stored in CircleCI. These may be stored in project environment variables or in contexts.<p>- We also recommend customers review internal logs for their systems for any unauthorized access starting from December 21, 2022 through today, January 4, 2023, or upon completion of your secrets rotation.<p>Additionally, if your project uses Project API tokens, we have invalidated those and you will need to replace them. You can find more information on how to do that in our documentation here.<p>We apologize for any disruption to your work. We take the security of our systems and our customers’ systems extremely seriously. While we are actively investigating this incident, we are committed to sharing more details with customers in the coming days.<p>Thank you for your urgent attention to rotating your secrets.

3 条评论

rmorlok超过 2 年前
More active thread on the issue:<p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=34255319" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=34255319</a>
rmorlok超过 2 年前
I received this email as well. Here is the blog post: <a href="https:&#x2F;&#x2F;circleci.com&#x2F;blog&#x2F;january-4-2023-security-alert&#x2F;" rel="nofollow">https:&#x2F;&#x2F;circleci.com&#x2F;blog&#x2F;january-4-2023-security-alert&#x2F;</a>
patatino超过 2 年前
What a fine word &quot;rotate&quot; is in this case