Skip to content

[ALERT TO USERS] Travis CI Security Breach - REMOVE Travis - Cycle Secure Env Vars  #141

@Lnaden

Description

@Lnaden

A massive security breach from Travis CI was detected on September 3. All Secure Environment Variables were injected into the Public Logs. Details here: https://twitter.com/peter_szilagyi/status/1437646118700175360

ALL USERS who still have Travis CI runs from the <=1.4 version of the cookiecutter and had any secure environment variables should immediately cycle the variables and secure files.

ALL USERS still using Travis CI should switch to GitHub Actions as soon as possible. The security breach was not handled with any haste or professionalism from the Travis CI team (see the linked tweet chain), and MolSSI has lost confidence in the product in its entirety.

This issue to be left open until further notice

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions