TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Public secrets exposure leads to supply chain attack on GitHub CodeQL

297 pointsby cyberbenderabout 2 months ago

9 comments

Syttenabout 2 months ago
An again this would not be so bad an impact if github finally pushed their immutable actions [1]. I sound like a broken record since I keep repeating that this would solve like 70%+ of the scope of attacks on gha today. You would think that the weekly disaster they have would finally make them launch it.<p>[1] <a href="https:&#x2F;&#x2F;github.com&#x2F;features&#x2F;preview&#x2F;immutable-actions" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;features&#x2F;preview&#x2F;immutable-actions</a>
评论 #43532082 未加载
nyrikkiabout 2 months ago
No mention why this temp token had rights to do things like create a new deployments and generate artifact attestations?<p>For their fix, they disabled debug logs...but didn&#x27;t answer if they changed the temp tokens permissions to something more appropriate for a code analysis engine.
评论 #43528290 未加载
评论 #43538350 未加载
评论 #43538343 未加载
评论 #43545199 未加载
评论 #43531049 未加载
评论 #43533461 未加载
ashishbabout 2 months ago
I am getting more and more convinced that CI and CD should be completely separate environments. Compromise of CI should not lead to token leaks related to CD.
评论 #43530510 未加载
评论 #43540155 未加载
juntoabout 2 months ago
They weren’t kidding on the response time. Very impressive from GitHub.
评论 #43527835 未加载
helsinkiabout 2 months ago
As someone with the last name Prater—derived from Praetorian—I really wish I owned praetorian.com.
评论 #43529724 未加载
评论 #43529805 未加载
udev4096about 2 months ago
Using public github actions is just asking for trouble and more so without analyzing the workflow&#x27;s procedure. Instead, just host one yourself using woodpecker or countless other great CI builders (circle, travis, gitlab, etc)
ryaoabout 2 months ago
I put CodeQL in use in OpenZFS PRs. This is not an issue for OpenZFS. None of our code is secret. :)
评论 #43529721 未加载
评论 #43528995 未加载
atxtechbroabout 2 months ago
Is this fixed?
评论 #43529418 未加载
bloqsabout 2 months ago
This sites performance is so bad i can barely scroll