- Sources: primary, discussion
- Summary: Strix reports that a scan of baseten.co subdomains found a Harbor registry with one public project allowing anonymous listing and pull of
baseten/baseten-app, whose image config carried a GitHub personal access token in a history[].created_by entry from a build step dated 2023-03-03 that expanded ARG GITHUB_TOKEN directly into a RUN command. The token was still live when tested in July 2026, resolved to basetenbot in the basetenlabs organization with repo scope, and carried admin and push on the product repository, on the flux-cd GitOps repository that drives their clusters and on the Homebrew tap that distributes their CLI, plus read and write on private repositories, and Strix states it stopped at read-only checks. Baseten made the project private and rotated the token on 2026-07-14, one day after the 2026-07-13 report, and closed the remaining findings on 2026-07-17. - Why it matters: Scrubbing a credential from an image's filesystem layers leaves it in the build history, which downloads along with the image.
send feedback on this story