GitHub breach highlights developer tools as part of attack surface
The recent GitHub incident + reports of a compromised VSCode extension feel like a wake up call for modern engineering teams.
A trusted extension already has repository access, local context, and developer trust. “That makes it a very different security problem than traditional infra attacks.”
Teams now need to treat developer environments, extensions, Github Apps, and local tooling with the same weight as production infrastructure.
What are other teams going to do after this I wonder.