Skip to content

Heroku security issue #1

Description

@CodefortheCarolinas

Hi, I’m passing along this message from Jess in the Code for America Brigade Programs Office.

Jennifer at Code for the Carolinas

“I'm contacting you in regards to a Heroku security breach that may have affected your projects: hurricane-florence-api, hurricane-florence-tilestache, hurricane-response-barry, and hurricane-response-smsbot. At this point, we are assuming that there was a full compromise of Heroku's infrastructure. We've started running an audit of all Brigade projects and request your assistance in updating your app.

Action Items:
Please rotate (update/reset) any secret keys you are using. If your app has access to other services (e.g. Twilio, Mailgun, AWS) through API keys or other credentials, please rotate those credentials as well.
Please confirm the status of your app by completing this form by EOD Tuesday, June 7.

If your project is inactive and can be shut down, please indicate that on the form. Note: Even if your app can be shut down, we'll still need you to rotate the secret keys on all external services you are using.

Thank you so much! Please send a message to brigade-info@codeforamerica.org if you have any questions”

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions