curuinor 6 days ago

hey, this is Howon from CodeRabbit. We use a cloud-provider-provided key vault for application secrets, including GH private key.

  • musicnarcoman 6 days ago

    So the CodeRabbit application with access to application secrets still runs in the same virtual machine as untrusted code from the outside?

  • megamorf 6 days ago

    Howon, you can stop posting that canned response. It's not helping the discussion in any way and matches the lack of detail the other commenters have pointed out.