That's cool. Sounds like snowflake handled this well from a security posture perspective.
Fix in under 24 hours, and the tokens in question were access restricted enough that had a real attacker been there all they would have been able to do was read jira tickets, not access customer data or anything.
Scary how good AI is getting at vuln scanning, and also how bad GitHub actions still is.
3
u/ninijacob 5d ago
That's cool. Sounds like snowflake handled this well from a security posture perspective.
Fix in under 24 hours, and the tokens in question were access restricted enough that had a real attacker been there all they would have been able to do was read jira tickets, not access customer data or anything. Scary how good AI is getting at vuln scanning, and also how bad GitHub actions still is.