TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Public secrets exposure leads to supply chain attack on GitHub CodeQL

297 点作者 cyberbender2 个月前

9 条评论

Sytten2 个月前
An again this would not be so bad an impact if github finally pushed their immutable actions [1]. I sound like a broken record since I keep repeating that this would solve like 70%+ of the scope of attacks on gha today. You would think that the weekly disaster they have would finally make them launch it.<p>[1] <a href="https:&#x2F;&#x2F;github.com&#x2F;features&#x2F;preview&#x2F;immutable-actions" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;features&#x2F;preview&#x2F;immutable-actions</a>
评论 #43532082 未加载
nyrikki2 个月前
No mention why this temp token had rights to do things like create a new deployments and generate artifact attestations?<p>For their fix, they disabled debug logs...but didn&#x27;t answer if they changed the temp tokens permissions to something more appropriate for a code analysis engine.
评论 #43528290 未加载
评论 #43538350 未加载
评论 #43538343 未加载
评论 #43545199 未加载
评论 #43531049 未加载
评论 #43533461 未加载
ashishb2 个月前
I am getting more and more convinced that CI and CD should be completely separate environments. Compromise of CI should not lead to token leaks related to CD.
评论 #43530510 未加载
评论 #43540155 未加载
junto2 个月前
They weren’t kidding on the response time. Very impressive from GitHub.
评论 #43527835 未加载
helsinki2 个月前
As someone with the last name Prater—derived from Praetorian—I really wish I owned praetorian.com.
评论 #43529724 未加载
评论 #43529805 未加载
udev40962 个月前
Using public github actions is just asking for trouble and more so without analyzing the workflow&#x27;s procedure. Instead, just host one yourself using woodpecker or countless other great CI builders (circle, travis, gitlab, etc)
ryao2 个月前
I put CodeQL in use in OpenZFS PRs. This is not an issue for OpenZFS. None of our code is secret. :)
评论 #43529721 未加载
评论 #43528995 未加载
atxtechbro2 个月前
Is this fixed?
评论 #43529418 未加载
bloqs2 个月前
This sites performance is so bad i can barely scroll