Company
Date Published
Author
Carole Winqwist
Word count
688
Language
English
Hacker News points
None

Summary

Mirantis, a company providing public cloud experiences across various infrastructures, faced challenges with secrets leakage via GitHub repositories as its development teams extensively used GitHub with an infrastructure as code mindset. To address this, Mirantis adopted GitGuardian, a tool capable of instantaneous secrets detection and alerting, which integrates with Slack for effective incident management. GitGuardian's ability to automatically identify publicly active developers and monitor their repositories was crucial, as it extended visibility beyond corporate repositories to personal ones where security oversight is typically lacking. The tool not only alerts but also aids in remediation through a feature called "Developer in the Loop," which streamlines the process of incident response by centralizing information and enabling efficient context understanding. Over two years, Mirantis has benefited from GitGuardian's customer-centric approach and is looking forward to further integration with other systems to enhance automation and detection capabilities.