
  <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
      <title>Chaos and Order</title>
      <link>https://www.youngju.dev/blog</link>
      <description>천천히 올바르게. AI Researcher &amp; DevOps Engineer Youngju&#39;s tech blog. GPU/CUDA, LLM, MLOps, Kubernetes AI workloads, distributed training, and data engineering.</description>
      <language>ko</language>
      <managingEditor>fjvbn2003@gmail.com (Youngju Kim)</managingEditor>
      <webMaster>fjvbn2003@gmail.com (Youngju Kim)</webMaster>
      <lastBuildDate>Fri, 12 Jun 2026 00:00:00 GMT</lastBuildDate>
      <atom:link href="https://www.youngju.dev/tags/secrets/feed.xml" rel="self" type="application/rss+xml"/>
      
  <item>
    <guid>https://www.youngju.dev/blog/devops/2026-06-12-developer-token-security-vscode-github.en</guid>
    <title>Where Developer Tokens Leak — The VSCode 1-Click Token Theft and Secret Hygiene</title>
    <link>https://www.youngju.dev/blog/devops/2026-06-12-developer-token-security-vscode-github.en</link>
    <description>Dissecting the June 2026 case of one-click GitHub token theft through a VSCode bug, this post traces the paths along which tokens leak in developer environments. It covers PAT permission design, token rotation, secret scanning, safe git-credential configuration, gitleaks, and how to eliminate long-lived tokens in CI with OIDC, all with practical configuration examples.</description>
    <pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>security</category><category>github</category><category>tokens</category><category>devops</category><category>secrets</category><category>oidc</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/devops/2026-06-12-developer-token-security-vscode-github.ja</guid>
    <title>開発者トークンが漏れる場所 — VSCode 1クリックトークン窃取事件とシークレット衛生</title>
    <link>https://www.youngju.dev/blog/devops/2026-06-12-developer-token-security-vscode-github.ja</link>
    <description>2026年6月に公開された、VSCodeのバグを介した1クリックでのGitHubトークン窃取事例を解剖し、開発環境でトークンが漏れる経路を追跡します。PATの権限設計、トークンのローテーション、secret scanning、git-credentialの安全な設定、gitleaks、CIでOIDCにより長期トークンをなくす方法まで、実践的な設定例で整理します。</description>
    <pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>security</category><category>github</category><category>tokens</category><category>devops</category><category>secrets</category><category>oidc</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/devops/2026-06-12-developer-token-security-vscode-github</guid>
    <title>개발자 토큰이 새는 곳들 — VSCode 1-Click 토큰 탈취 사건과 시크릿 위생</title>
    <link>https://www.youngju.dev/blog/devops/2026-06-12-developer-token-security-vscode-github</link>
    <description>2026년 6월 공개된 VSCode 버그를 통한 1-click GitHub 토큰 탈취 사례를 해부하고, 개발 환경에서 토큰이 새는 경로를 추적합니다. PAT 권한 설계, 토큰 회전, secret scanning, git-credential 안전 설정, gitleaks, CI에서 OIDC로 장기 토큰을 없애는 방법까지 실전 설정 예제로 정리합니다.</description>
    <pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>security</category><category>github</category><category>tokens</category><category>devops</category><category>secrets</category><category>oidc</category>
  </item>

    </channel>
  </rss>
