Osipov
  • Home
  • About
Sign in Subscribe

Coming soon

Anton Osipov

Anton Osipov

01 Sep 2025
Coming soon

Read more

The Hard Truth: GitHub Secrets Are Not a Security Boundary (Unless You're on Enterprise)

TL;DR: On GitHub Free and Team plans, if a workflow can run, it can steal your secrets. Code reviews and branch protections happen too late to save you. If you need to store production SSH or Kubernetes credentials inside GitHub Actions, GitHub Enterprise is no longer an optional upgrade—

By Anton Osipov 28 Jan 2026
Osipov
  • Sign up
Powered by Ghost

Osipov

Thoughts, stories and ideas.