Comment by philipkiely

8 hours ago

Hey all Philip from Baseten here.

Posting this on behalf of our security team. I wanted to confirm that we collaborated with Strix on the remediation of the reported vulnerability. We thank Strix for their responsible disclosure. We took immediate steps to invalidate the leaked key and remove the public container image. Our logs confirm the vulnerability was never exploited and no customer data was exposed.

+1 -- kudos to the Baseten team for their super professional response to all of this, it is clear why they are a generational company (-- Alex from Strix)

  • What distinguishes their response from non-generational companies? Do others fail to rotate their exposed github secrets that have admin access?

    • see, non-generational companies often miss the chance to turn penetration testing into a marketing opportunity