logoalt Hacker News

darnthenuggetsyesterday at 1:35 PM1 replyview on HN

Both of these attacks have used trufflehog. Is there an out of the box way to block that executable by name or signature?


Replies

jamietannayesterday at 9:51 PM

I'd say an alternative question is "how can we stop storing secrets in source control" so then tools like Trufflehog can't find them :)