upvote
Given the build is from 2023 one would expect that at least the token would have been rotated, and I suspect some of these compliance checks do require rotation of tokens/passwords.

That said, the whole compliance industry is a joke.

reply
Box checking is an important business!
reply
I can’t help noticing that an LLM can check boxes.
reply
tokens yes, password rotation, no.

In 2017:

> NIST changed the guidance with SP 800-63B, published June 2017. It explicitly said:

"Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically)."

Instead, passwords should be changed when there is evidence they have been compromised, not every 30/60/90 days.

reply
Unless github had regulated data, unlikely, the legal implications are few. Document the issue, remediate and no findings on the next audit. Done.
reply