3 ms·
The point is the developer was not allowed, by github, to break his own copy, they suspended his account. This is a reminder of how much power you cede to Micr
by fivelessminutes 5y ago
The point is the developer was not allowed, by github, to break his own copy, they suspended his account.
This is a reminder of how much power you cede to Microsoft when you decide to make yourself completely reliant on their free services.
- remram 5y agoI think it would have been fine if that code had stayed in a separate branch, or a separate repository. You can create a repo and put all the silly print statements and infinite loops you want, and Microsoft will leave you alone. If you mount a supply-chain attack, deliberately overwriting a package you know people are relying on with code that will break their systems, that is something else. Maybe GitHub should have frozen only this one repo, though I doubt that would have made a difference in the public response. But you can't really say that they banned someone's private little experiment here. As to the power you cede to Microsoft, that is a weird way to phrase it. Microsoft gave you the right to use their platform, for free. All they did is take that away. That is not much power at all.
- GauntletWizard 5y agoI want to point out my latest example of a supply chain attack that's going on all the time: GitHub Actions GitHub Actions uses tags to represent it's versions, which would be great if GitHub locked down tags. They don't. Every GitHub Action I encountered in my first foray into the technology a couple weeks ago included a "Publish" script - that as it's first action, deleted a tag! And then reused that tag. This is absolutely a supply chain attack, if not a malicious one.
- remram 5y agoYeah I feel uneasy about using third-party GitHub actions. I suppose you could use `action@<hash>` syntax instead of a tag... At least actions are usually self-contained, you don't have the same problem of transitive dependencies you have in npm.
- ViViDboarder 5y agoThis came up in another thread on here about the event, but how does this action outwardly appear like anything other than his account being compromised to some kind of moderator? It seems like access was restored pretty quickly because within hours of the whole thing going down and reading about him being banned, I could see it was already restored. Anyway, if my account started to sabotage my projects, I’d hope GitHub would suspend it until there was a better understanding of what was going on.
- pengaru 5y agoIt's github's copy, not his. He's effectively a volunteer maintainer of a github/MS owned repository.