See? I TOLD you all to leave GitHub! "Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks"
2026-07-07 00:58 UTC
Don’t say I didn’t warn you…
Replies (2)
-
@A_norny_mousse@piefed.zip 2026-07-07 01:32
That sounds big & creepy: On Microsoft’s Azure Sentinel, for example, Novee found a comment on a PR that could run anonymous attacker code on Microsoft’s CI and steal a non-expiring GitHub App key. I wonder if/how alternative VCS platforms that provide similar workflow services are affected.
-
@minfapper@piefed.social 2026-07-07 06:09
The core of the problem trickles down to weak CI/CD configurations that grant pull requests (PRs) more permissions than they should have. How exactly do their competitors like codeberg do better in preventing that?