Published
Accidental CI secret leaks: logs, artifacts, and core dumps
How CI credentials accidentally reach logs, generated configuration, test reports, caches, and core dumps—and what to inspect before uploading diagnostics.
Runnerless Stories
Practical explanations of CI behavior, security controls, and the tradeoffs behind our plans.
Published
How CI credentials accidentally reach logs, generated configuration, test reports, caches, and core dumps—and what to inspect before uploading diagnostics.
Published
How GitHub and CircleCI controls, npm and crates.io trusted publishing, and a proposed isolated publisher reduce credential exposure—and where their protection ends.
Published
Let the publishing service fetch and verify CI artifacts, keeping destination credentials out of build jobs and checking source, commit, and exact bytes before publication.
Allow optional Datadog performance diagnostics and masked session replay. Signup works either way. Details