Home / Companies / CircleCI / Blog / Post Details
Content Deep Dive

CircleCI security alert: Rotate any secrets stored in CircleCI (Updated Jan 13)

Blog post from CircleCI

Post Details
Company
Date Published
Author
Rob Zuber
Word Count
2,692
Company Posts That Month
2
Language
English
Hacker News Points
-
Post removed?
No
Summary

In response to a security incident disclosed on January 4, 2023, CircleCI has taken multiple steps to mitigate potential risks and ensure the security of its platform. These measures include partnering with AWS to notify customers about potentially impacted tokens, rotating GitHub OAuth tokens, and revoking all personal and project API tokens created before January 5, 2023. CircleCI has also provided instructions for customers to rotate secrets and keys stored on their platform and has updated their tools to assist in discovering stored secrets. Despite the incident, CircleCI assures customers that they can continue to build and that no unauthorized access has occurred. The company emphasizes the importance of rotating access keys and secrets and offers support through its engineering and security teams, while also working closely with third-party investigators to validate their actions.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 13 675 79 48 +107%
MCP 1 10 5 3 +233%
Platform Engineering 1 224 44 29 +59%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.