Home / Companies / Arnica / Blog / Post Details
Content Deep Dive

How to ensure you don’t have Sourcegraph secrets in source code

Blog post from Arnica

Post Details
Company
Date Published
Author
Nir Valtman
Word Count
630
Company Posts That Month
3
Language
English
Hacker News Points
3
Post removed?
No
Summary

On August 30, 2023, Sourcegraph's Head of Security revealed that a hacker gained administrative access to Sourcegraph and may have accessed user information. The breach occurred when a Sourcegraph engineer accidentally committed code containing an active site-admin token with extensive privileges. A malicious user exploited the exposed credentials to create a proxy application granting free access to Sourcegraph APIs, resulting in 2 million views within hours. The exposure affected Sourcegraph.com's public code only, and while data was potentially accessed, its extent remains uncertain. Arnica has introduced a custom validator for Sourcegraph tokens as part of their secrets detection and validation service, which can help prevent similar issues by alerting developers to the presence of secrets in source code and offering assistance in removing them.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 6 525 94 58 -33%
LLM 1 2,134 271 94 -26%
Real-time 1 2,216 526 161 -9%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.