Skip to content

Security FAQ

Yuxiang Huang edited this page Jan 4, 2026 · 3 revisions

You might wonder what if a malicious GitHub user tries to become a contributor using someone else's Andrew ID.

Well, Vault, which we use to store our secrets, requires CMU SAML login to view the secrets, so the malicious actor still won't have access to the secrets nor any information accessible to only CMU students.

Clone this wiki locally