Nullcon Goa 2025 | Large-Scale Exposure Of Orphaned Commits On Major Git Platforms by Kumar Ashwin
About this talk
This talk explores the critical importance of version control in modern development, specifically focusing on the security risks associated with dangling commits in GitHub, GitLab, and Bitbucket. The speaker details how these leftover commits, often containing sensitive information such as API keys and credentials, remain in repository history despite efforts to remove them. The session outlines methods for identifying and enumerating these hidden vulnerabilities on a large scale, highlighting alarming findings from extensive research. Practical solutions and best practices for maintaining effective repository hygiene are also discussed, emphasizing the need for organizations to safeguard against both visible and hidden threats in their repositories.
More from this event
See all 30 talks →
Nullcon Goa 2025: Securing the chains: Building defensive layers for software supply chains
38:14
Nullcon Goa 2025 | Panel: Modernizing Security Architecture: Platforms or Best-of-Breed, What Works?
44:47
Nullcon Goa 2025: Panel | Cyber Fusion Center: The Command Center For Integrated Cyber Defense
42:01
Nullcon Goa 2025 | Unlocking India’s cyber potential through policy, innovation, and partnerships
42:24