GitHub’s Post

View organization page for GitHub, graphic

4,156,035 followers

🎉 Write safer code with new vulnerability prevention features in GitHub Copilot 🔒 ✅

Navarre Trousselot

Founder of Navexa, empowering investors to track performance, calculate taxes, and build wealth. Sharing fintech and investing insights.

1y

This needs to go a bit further. Co-pilot has been writing out peoples API keys for various different services. I got auto recommended someones mixpanel api key a couple of days a go.

to prevent sql injection a better approach is to use store procedures and avoid types like strings in params to pass into the stores procedures (sometimes just cant and its ok), with this you can avoid build "queries everywhere" in your backend repo (what happen if your table change the name or just delete one column?, is going to fail everywhere :O), also you can use some good lib utility to call this SP, usually they cover security breaches, another approach is just use an ORM solution, but this is another thing. IMHO :)

Navarre Trousselot there is a solution to CoPilot suggestions of other people's code (including API keys) GitHub must retrain a completely new model only on open-source licensed code. We do that...

Ido Tzur Tal

Technical Support Engineer

1y

Itay Hayun אחי זה אתה

ROCIO HERRERA O

Propietario de la empresa en ALESFORCE

6mo

GRACIAS POR EL MATERIAL ENVIADO A MI CORREO ELECTRONICO ROCIO HERRERA OBESO GRUPO MANAJECTMENT INTERNACIONAL GLOBAL

Like
Reply
Yi leng Yao

Building with AI | Senior Software Engineer | Tech Lead

1y

Use jOOQ, thank me later.

Like
Reply
Reeh Martins

"CUIDADO PARA QUE NA BUSCA DO MELHOR VC NAO PERCA O MELHOR QUE JA TEM"🫰

1y

Aprende Johnny kkkkk qnt mas conhecimento melhor kkkk

Like
Reply
Sama Mansori

Health And Wellness Coach at Airbnb

6mo

چجوری؟ 

Like
Reply
Mikael R.

Kärnuppdragare Samhall AB Karlsborg

1y

Very useful

Like
Reply
Marilda Sousa de jesus

Cuidador doméstico na sebastiao fraco de lima

1y

Como ficiona

Like
Reply
See more comments

To view or add a comment, sign in

Explore topics