{"id":1173126,"date":"2024-03-01T04:43:30","date_gmt":"2024-03-01T06:43:30","guid":{"rendered":"https:\/\/teknomers.com\/fr\/github-deploie-une-protection-push-par-defaut-contre-lanalyse-secrete-pour-les-referentiels-publics\/"},"modified":"2024-03-01T04:43:35","modified_gmt":"2024-03-01T06:43:35","slug":"github-deploie-une-protection-push-par-defaut-contre-lanalyse-secrete-pour-les-referentiels-publics","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/github-deploie-une-protection-push-par-defaut-contre-lanalyse-secrete-pour-les-referentiels-publics\/","title":{"rendered":"GitHub d\u00e9ploie une protection push par d\u00e9faut contre l&#8217;analyse secr\u00e8te pour les r\u00e9f\u00e9rentiels publics"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">01 mars 2024<\/span><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">R\u00e9daction<\/span><\/span><span class=\"p-tags\">DevSecOps \/ Cybers\u00e9curit\u00e9<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a rel=\"nofollow\" href=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2024\/03\/GitHub-deploie-une-protection-push-par-defaut-contre-lanalyse-secrete.jpg\" style=\"clear: left; display: block; float: left; text-align: center;\"><\/a><\/div>\n<p>GitHub a annonc\u00e9 jeudi qu&#8217;il activait par d\u00e9faut la protection contre les analyses secr\u00e8tes pour toutes les pouss\u00e9es vers des r\u00e9f\u00e9rentiels publics.<\/p>\n<p>&#8220;Cela signifie que lorsqu&#8217;un secret pris en charge est d\u00e9tect\u00e9 lors d&#8217;une transmission vers un r\u00e9f\u00e9rentiel public, vous aurez la possibilit\u00e9 de supprimer le secret de vos commits ou, si vous consid\u00e9rez que le secret est s\u00fbr, de contourner le blocage&#8221;, Eric Tooley et Courtney Claessens <a rel=\"nofollow noopener\" href=\"https:\/\/github.blog\/2024-02-29-keeping-secrets-out-of-public-repositories\/\" target=\"_blank\">dit<\/a>.<\/p>\n<p><a rel=\"nofollow noopener\" href=\"https:\/\/docs.github.com\/en\/code-security\/secret-scanning\/push-protection-for-repositories-and-organizations\" target=\"_blank\">Protection contre la pouss\u00e9e<\/a> \u00e9tait <a rel=\"nofollow noopener\" href=\"https:\/\/github.blog\/2023-08-09-enhanced-push-protection-features-for-developers-and-organizations\/\" target=\"_blank\">pilot\u00e9 pour la premi\u00e8re fois<\/a> en tant que fonctionnalit\u00e9 opt-in en ao\u00fbt 2023, bien qu&#8217;elle soit en test depuis avril 2022. Elle est devenue g\u00e9n\u00e9ralement disponible en mai 2023.<\/p>\n<p>Le <a rel=\"nofollow noopener\" href=\"https:\/\/docs.github.com\/en\/code-security\/secret-scanning\/about-secret-scanning\" target=\"_blank\">analyse secr\u00e8te<\/a> La fonctionnalit\u00e9 est con\u00e7ue pour identifier plus <a rel=\"nofollow noopener\" href=\"https:\/\/docs.github.com\/en\/code-security\/secret-scanning\/secret-scanning-patterns\" target=\"_blank\">200 types de jetons<\/a> et mod\u00e8les de plus de 180 fournisseurs de services afin d&#8217;emp\u00eacher leur utilisation frauduleuse par des acteurs malveillants. <\/p>\n<div class=\"check_two clear bobbob\"><center class=\"cf\"><a rel=\"nofollow noopener\" href=\"https:\/\/thehackernews.uk\/delinea728\" target=\"_blank\" title=\"Cybersecurity\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"La cyber-s\u00e9curit\u00e9\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2024\/02\/1708012425_568_Les-pirates-informatiques-russes-de-Turla-ciblent-les-ONG-polonaises.jpg\" width=\"727\" height=\"90\"\/><\/a><\/center><\/div>\n<p>Ce d\u00e9veloppement intervient pr\u00e8s de cinq mois apr\u00e8s que la filiale de Microsoft a \u00e9tendu l&#8217;analyse des secrets pour inclure les contr\u00f4les de validit\u00e9 des services populaires tels qu&#8217;Amazon Web Services (AWS), Microsoft, Google et Slack.<\/p>\n<p>Cela fait \u00e9galement suite \u00e0 la d\u00e9couverte d&#8217;une attaque de \u00ab\u00a0confusion de repo\u00a0\u00bb ciblant GitHub qui inonde la plate-forme d&#8217;h\u00e9bergement de code source avec des milliers de r\u00e9f\u00e9rentiels contenant des logiciels malveillants obscurcis capables de voler des mots de passe et des crypto-monnaies sur les appareils des d\u00e9veloppeurs.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a rel=\"nofollow\" href=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2024\/03\/GitHub-deploie-une-protection-push-par-defaut-contre-lanalyse-secrete.png\" style=\"clear: left; display: block; float: left; text-align: center;\"><img decoding=\"async\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2024\/03\/GitHub-deploie-une-protection-push-par-defaut-contre-lanalyse-secrete.png\" alt=\"GitHub\" border=\"0\" data-original-height=\"455\" data-original-width=\"873\" title=\"GitHub\"\/><\/a><\/div>\n<p>Les attaques repr\u00e9sentent une autre vague de la m\u00eame campagne de distribution de logiciels malveillants r\u00e9v\u00e9l\u00e9e par Phylum et <a rel=\"nofollow noopener\" href=\"https:\/\/www.trendmicro.com\/en_us\/research\/23\/j\/infection-techniques-across-supply-chains-and-codebases.html\" target=\"_blank\">Tendance Micro<\/a> l&#8217;ann\u00e9e derni\u00e8re, en exploitant de faux packages Python h\u00e9berg\u00e9s sur des r\u00e9f\u00e9rentiels clon\u00e9s et trojanis\u00e9s pour diffuser un malware voleur appel\u00e9 <a rel=\"nofollow noopener\" href=\"https:\/\/github.com\/Inplex-sys\/BlackCap-Grabber-NoDualHook\" target=\"_blank\">Pince \u00e0 Capuchons Noirs<\/a>.<\/p>\n<p>&#8220;Les attaques de confusion sur les d\u00e9p\u00f4ts reposent simplement sur le fait que les humains choisissent par erreur la version malveillante plut\u00f4t que la vraie, en utilisant parfois \u00e9galement des techniques d&#8217;ing\u00e9nierie sociale&#8221;, Apiiro <a rel=\"nofollow noopener\" href=\"https:\/\/apiiro.com\/blog\/malicious-code-campaign-github-repo-confusion-attack\/\" target=\"_blank\">dit<\/a> dans un rapport cette semaine.<\/p>\n<p><\/p>\n<div class=\"cf note-b\">Vous avez trouv\u00e9 cet article int\u00e9ressant ?  Suivez-nous sur <a rel=\"nofollow noopener\" href=\"https:\/\/twitter.com\/thehackersnews\" target=\"_blank\">Twitter <i class=\"icon-font icon-twitter\">\uf099<\/i><\/a>  et <a rel=\"nofollow noopener\" href=\"https:\/\/www.linkedin.com\/company\/thehackernews\/\" target=\"_blank\">LinkedIn<\/a> pour lire plus de contenu exclusif que nous publions.<\/div>\n<\/div>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><br \/>\n<br \/><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2024\/03\/github-rolls-out-default-secret.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\ue80201 mars 2024\ue804R\u00e9dactionDevSecOps \/ Cybers\u00e9curit\u00e9 GitHub a annonc\u00e9 jeudi qu&#8217;il activait par d\u00e9faut la protection contre les analyses secr\u00e8tes pour toutes les pouss\u00e9es vers des r\u00e9f\u00e9rentiels publics. &#8220;Cela signifie que lorsqu&#8217;un secret pris en charge est d\u00e9tect\u00e9 lors d&#8217;une transmission vers un r\u00e9f\u00e9rentiel public, vous aurez la possibilit\u00e9 de supprimer le secret de vos commits [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1173127,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[200292,4168,841,4165,4161,200267,10930,7050,50438,4159,4171,10674,65,200271,200268,200269,200270,164,185,6845,16405,40602,58986,15113,128318,4172,4169,196,4166,4164],"class_list":["post-1173126","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-actualites-sur-la-cybersecurite","tag-comment-pirater","tag-contre","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-cyberactualites","tag-defaut","tag-deploie","tag-github","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-lanalyse","tag-les","tag-logiciel-malveillant-rancongiciel","tag-mises-a-jour-sur-la-cybersecurite","tag-nouvelles-des-pirates","tag-nouvelles-sur-le-piratage","tag-par","tag-pour","tag-protection","tag-publics","tag-push","tag-referentiels","tag-secrete","tag-securite-des-informations","tag-securite-informatique","tag-securite-internet","tag-une","tag-violation-de-donnees","tag-vulnerabilite-logicielle"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/1173126","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=1173126"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/1173126\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/1173127"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=1173126"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=1173126"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=1173126"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}