This repository has been archived by the owner on Oct 15, 2024. It is now read-only.
Replies: 1 comment
-
Thanks for the heads-up. This attack vector shouldn't affect us since all legitimate Renovate PRs to APS originate from the repository itself, so it's very easy to spot malicious ones. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
I've just seen this HN post, which is about malicious actors spoofing commits to make them look like they're from Github's dependabot, and thus getting malicious code into projects.
Because this project makes heavy use of renovate (a similar bot from my understanding) and given the project's extra-sensitive nature, I thought it was worth mentioning here.
Beta Was this translation helpful? Give feedback.
All reactions