info on the github breach appears to only be available on xitter 🙄 , I fished it out for you.

#github

@0xabad1dea

They wrote:

> "2/ Our current assessment is that the activity involved exfiltration of GitHub-internal repositories only. […]
3/ We moved quickly to reduce risk. Critical secrets were rotated yesterday and overnight with the highest-impact credentials prioritized first."

Do they really put "Critical secrets" in their "GitHub-internal repositories" !?

@benoitb every large organization, knowingly or unintentionally (usually both), has internal secrets embedded in their internal codebase. so yeah