4 ms·
Any large company is going to frown heavily on using references to some sketchy third party dev's repo. Large companies don't like that and it rightfully raises
by NathanKP 6y ago
Any large company is going to frown heavily on using references to some sketchy third party dev's repo. Large companies don't like that and it rightfully raises all kinds of appsec concerns because @dessant could easily change their Github Action to do something malicious.
Here's how I'd guess this entire process went:
1. FB appsec: "wtf are you doing referencing this guy's Github Action in our codebase? We don't own that and if he chooses to change something we get hacked"
2. FB employee: "okay fine I'll fix it"
3. FB employee: creates official version for FB to use, that can't be mutated outside of FB oversight
- jen20 6y agoIf this was how things went down, it was a terrible implementation of a fix - you'd expect it to be under a Facebook namespace rather than the employee's personal account - if the employee leaves, they instantly become a "sketchy third party dev".
- baby 6y agoYup, this dependency seemed like a pretty big risk