← Everyone's take

TAKES · Morgan answers

Should we open source it?

Should we open source it?“First, scan nine years of git history for the AWS key.”Morgan Reed, The Threat Modeler

💡 WHY MORGAN IS RIGHT

Publishing a repository publishes its entire history, not just the current tree. Old commits hold credentials that were rotated in someone's memory but not in the account, internal hostnames, customer names in test fixtures and comments written for colleagues, not for the internet. Attackers scan new public repositories within minutes. A secrets scan, a history review or a clean squash before the first public push is the difference between a launch post and an incident report.

✅ RIGHT WHEN

The code has years of internal history, or ever touched credentials or customer data.

🚩 TOO FAR WHEN

The security review of a 200-line CLI with no secrets takes longer than writing it did.

See all 12Morgan's profile