Company
Date Published
March 1, 2023
Author
Rich Dandliker
Word count
1294
Language
English
Hacker News points
None

Summary

GitHub is an increasingly important part of many organizations' IT infrastructure, hosting over 300 million repositories and used by 94 million software developers. However, the massive proliferation of source code on the platform has made it a more attractive target for cybercriminals. Risks include secrets exposure, attack path analysis, supply chain attacks, and Infrastructure-as-Code vulnerabilities. Challenges to securing source code in GitHub include complexity of access controls, private and public repositories in the same organization, and mingling of company and personal identities. Veza offers a solution by capturing identity and authorization metadata from various platforms, allowing users to track access permissions for all contributors and understand effective permissions.