Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Heroku security issue #1

Open
CodefortheCarolinas opened this issue Jun 2, 2022 · 0 comments
Open

Heroku security issue #1

CodefortheCarolinas opened this issue Jun 2, 2022 · 0 comments

Comments

@CodefortheCarolinas
Copy link

Hi, I’m passing along this message from Jess in the Code for America Brigade Programs Office.

Jennifer at Code for the Carolinas

“I'm contacting you in regards to a Heroku security breach that may have affected your projects: hurricane-florence-api, hurricane-florence-tilestache, hurricane-response-barry, and hurricane-response-smsbot. At this point, we are assuming that there was a full compromise of Heroku's infrastructure. We've started running an audit of all Brigade projects and request your assistance in updating your app.

Action Items:
Please rotate (update/reset) any secret keys you are using. If your app has access to other services (e.g. Twilio, Mailgun, AWS) through API keys or other credentials, please rotate those credentials as well.
Please confirm the status of your app by completing this form by EOD Tuesday, June 7.

If your project is inactive and can be shut down, please indicate that on the form. Note: Even if your app can be shut down, we'll still need you to rotate the secret keys on all external services you are using.

Thank you so much! Please send a message to [email protected] if you have any questions”

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant