GitHub
"That’s definitely the hottest topic right now in tech for us across the bank,”
"You have to be intentional about designing for real people who are not security experts."
"We operate with the assumption that a sophisticated nation state threat actor is always active inside the organisation"
“Our model targets the most common vulnerable coding patterns, including hardcoded credentials, SQL injections, and path injections" says "refounded" company.
"No-one has the time or sanity to audit every thing every build process pulls in."
Several weeks after a major security incident at Heroku, the company said this week it "will not be reconnecting to GitHub until we are certain that we can do so safely, which may take some time" -- as news of the early April breach continues to percolate slowly