Hey all Philip from Baseten here.
Posting this on behalf of our security team. I wanted to confirm that we collaborated with Strix on the remediation of the reported vulnerability. We thank Strix for their responsible disclosure. We took immediate steps to invalidate the leaked key and remove the public container image. Our logs confirm the vulnerability was never exploited and no customer data was exposed.
> Our logs confirm
You retain all logs back through to (at least) March 2023?
You don't?
For some stuff, I've got logs going back to 1993...
+1 -- kudos to the Baseten team for their super professional response to all of this, it is clear why they are a generational company (-- Alex from Strix)
What distinguishes their response from non-generational companies? Do others fail to rotate their exposed github secrets that have admin access?
I think that many other companies (especially larger ones, I suppose) don't respond as promptly to security issues.
see, non-generational companies often miss the chance to turn penetration testing into a marketing opportunity