node
node copied to clipboard
Securing CI services
We have got complain from german CERT that our redis is unsecured. It turns out that this redis is being launched during CI process.
Most likely this "vulnerability" would not have any security implications, but we must react to CERT complains. My suggestion is to bind such processes locally if possible or at least change some default credentials / ports so that default scanners would not complain about possible issues.