2 ms·
Whew, that's good to hear. I assume anyone trying to inject malicious code is going to try to do so in a way that doesn't go through normal code review channels
by codezero 6y ago
Whew, that's good to hear. I assume anyone trying to inject malicious code is going to try to do so in a way that doesn't go through normal code review channels.
- thatsamonad 6y agoTrue. However, hopefully that’s being mitigated through things like not allowing authors to review their own commits, not using the same accounts to push code changes and do deployments (i.e. having a read-only account for deployments), etc. However, if it were an admin account that were breached that would definitely make it possible to circumvent any number of protections in place.