Settings

Theme

Securing the Git push pipeline: Responding to a critical remote code execution

github.blog

14 points by samtrack2019 8 hours ago · 2 comments

Reader

philipwhiuk an hour ago

Nothing on auditing other fields? Nothing on how it escaped test coverage? No fuzzing?

time4tea 4 hours ago

I mean, sure.

But what about allowing user inputs in trusted fields,

Or allowing switching environments per request, on inputs from users

Or allowing requests in a user context to access storage from another

Or storing everything in plaintext on a node that everything can access

Or not validating user inputs

Or...

Its not a success story.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection