NHacker Next
  • new
  • past
  • show
  • ask
  • show
  • jobs
  • submit
Securing the Git push pipeline: Responding to a critical remote code execution (github.blog)
5 days ago [-]
philipwhiuk 5 days ago [-]
Nothing on auditing other fields? Nothing on how it escaped test coverage? No fuzzing?
time4tea 5 days ago [-]
I mean, sure.

But what about allowing user inputs in trusted fields,

Or allowing switching environments per request, on inputs from users

Or allowing requests in a user context to access storage from another

Or storing everything in plaintext on a node that everything can access

Or not validating user inputs

Or...

Its not a success story.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact
Rendered at 06:37:01 GMT+0000 (UTC) with Wasmer Edge.