4 ms·
I can imagine a scenario where a malicious employee is intentionally injecting malicious code (backdoor, whatever) and wants that commit tied back to someone el
by ppierald 11y ago
I can imagine a scenario where a malicious employee is intentionally injecting malicious code (backdoor, whatever) and wants that commit tied back to someone else (their enemy, boss).
- ikeboy 11y agoIf they have push access, would github log who actually pushed it (i.e. ssh key)?
- rectang 11y agoYes, Github's authenticated push logs will tell you that. However, Github won't make those public, because they consider user identification private info. (Or at least they won't provide those push logs to the Apache Software Foundation, which is how I know this.)