Jesus H...
See title.
Cloud comms platform Twilio has confirmed its private GitHub repositories were cloned after it became the latest casualty of the compromised credential-stealing Codecov script. Codecov, a cloud-based tool for assessing how much code is covered by software tests, revealed last month that a script called Bash Uploader had been …
"A notable aspect of Twilio's report is what it says under the heading "What are we doing to prevent similar issues in the future?" The company said it evaluates its suppliers for security, and has developed a service called Deadshot that scans GitHub pull requests to prevent secrets or insecure code being committed to its repository."
Masterful restraint on the part of the author, Tim Anderson. Notable aspect indeed. I wrote a whole bunch more but then deleted it, because everybody here, unlike Codecov, Twilio, et al, already sees the issue with complete clarity.