Sheldan@programming.dev to Programming@programming.dev · 2 months agoMalicious code injection by compromised pull request branch namesgithub.comexternal-linkmessage-square10fedilinkarrow-up185
arrow-up185external-linkMalicious code injection by compromised pull request branch namesgithub.comSheldan@programming.dev to Programming@programming.dev · 2 months agomessage-square10fedilink
minus-squareThinker@lemmy.worldlinkfedilinkarrow-up18·2 months agoDing ding ding! We have a winner! It’s a third-party GitHub Action that is passing the branch name directly to Bash. So to be clear, not GitHub’s fault.
Ding ding ding! We have a winner!
It’s a third-party GitHub Action that is passing the branch name directly to Bash. So to be clear, not GitHub’s fault.