Post #2978557
2026-05-12 18:48 UTC
@prioinv@hachyderm.io in principle nothing would break, but I think it would still be pretty exploitable in practice due to people granting elevated permissions to those jobs
Replies (1)
-
@prioinv@hachyderm.io 2026-05-12 19:06
@yossarian@infosec.exchange yeah, it would be more visible at least I imagine (you need to push a commit to main to poison the cache, which you can't hide again if branch protection is on). But in the tanstack case, where it was read-only, it would have stopped things from what I understand.