2023-11-16
🔍 Tom Forbes & GitGuardian revealed a study on the number of hardcoded credentials in PyPI packages. 3,938 unique secrets found! 768 valid secrets among them! 2,922 projects included one secret! Want the study? https://s.gitguardian.com/3f2c1e #CyberSecurity #Python #PyPI #GitGuardian
Ars Technica
GitGuardian: nearly 3K of the 450K projects submitted to PyPI exposed at least one credential in code, like API keys, including some from “very large companies”
Many transgressions come from “very large companies that have robust security teams.”
The State of Pypi Secrets Sprawl... A growing problem source: https://s.gitguardian.com/g3p #PyPi #Cybersecurity #Secrets [image]
Ars Technica
GitGuardian: nearly 3K of the 450K projects submitted to PyPI exposed at least one credential in code, like API keys, including some from “very large companies”
Many transgressions come from “very large companies that have robust security teams.”