Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Do people put secrets in Atlassian tools? Sounds like the worst place to do that. If anything I would want my main wiki/project/ticket management tools/code repos to be as open as possible (I mean to read) to help collaboration.

The part about not having guardrail against calls to external urls is wild though.



Not "secrets" usually, but people tend to consider the corporate IP embodied in Jira to be classified as something other than Public.

Teamwork Graph exposes all the people working on stealth products with code names right alongside their other work anyway.


I was thinking within the scope of a single tenant which is the scope of the prompt injections issues mentionned in this article.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: