DEV Community

Discussion on: Disclosing a State of JavaScript/State of CSS Data Leak

Collapse
 
aarongoldenthal profile image
Aaron Goldenthal

Transparent disclosures are always appreciated. You may also want to look at tools like gitleaks to prevent secrets from being committed.

Collapse
 
ericburel profile image
Eric Burel

Yes we are setting it up: github.com/VulcanJS/vulcan-next/is...
It's not so obvious to setup though, and I still need to test if it actually would have caught this one leak for instance, or more probables one (eg leaks in dotenv files), which explains why this tool is not common enough