I highly recommend the comments, particularly this from excors: <a href="https://lwn.net/Articles/1001309/" rel="nofollow">https://lwn.net/Articles/1001309/</a><p>I am far from an expert on CI / GitHub, so when I saw this attack I thought "sure I guess that could happen" but was pretty baffled as to how beyond some hand-waving about escape characters and the dangers of mixing data and code.