Elektrine lite

← Feed

@Dymonika@lemmy.ml

See? I TOLD you all to leave GitHub! "Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks"

2026-07-07 00:58 UTC

Don’t say I didn’t warn you…

Replies (2)

  • @A_norny_mousse@piefed.zip 2026-07-07 01:32

    That sounds big & creepy: On Microsoft’s Azure Sentinel, for example, Novee found a comment on a PR that could run anonymous attacker code on Microsoft’s CI and steal a non-expiring GitHub App key. I wonder if/how alternative VCS platforms that provide similar workflow services are affected.

    Open ##3640403

  • @minfapper@piefed.social 2026-07-07 06:09

    The core of the problem trickles down to weak CI/CD configurations that grant pull requests (PRs) more permissions than they should have. How exactly do their competitors like codeberg do better in preventing that?

    Open ##3642003