Secrets in Github are backed-up
Open
security
- Dominant language
- Python
- Stars
- 46.9k
- Forks
- 17.8k
- Avg merge
- 2d 7h
- Merged PRs (30d)
- 484
Description
Today some secrets (which are.. secret :-D) are write-only in Github and it is not possible to get them our (besides revealing them from an Action.
For DR purposes we should have a secondary copy (proposal: 1Password) to be able to restore if deleted by accident.
Contributor guide
Research direction
The issue does not identify files, tests, or entry points. Start by locating how the project’s GitHub secrets are managed and evaluating the proposed 1Password backup; completion requires an agreed and verified disaster-recovery path.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github
- Domain
- devops, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100