Securing the open source supply chain by scanning for package registry credentials

Securing the open source supply chain by scanning for package registry credentials

Articles

An introduction to secrets, GitHub secret scanning, the open source supply chain, and why revoking package registry credentials is so important.