4 ms·
If they use the same runners, couldn’t the attacker just wait? The runners would need to be sequestered too
by mlazos 3y ago
If they use the same runners, couldn’t the attacker just wait? The runners would need to be sequestered too
- kevin_nisbet 3y agoAbsolutely. The real difficulty is tests on PR are by definition remote code execution by an untrusted source, so a full risk analysis and hardening needs to be done. Here's a similar mistake on an OSS repo a company I worked for made: https://goteleport.com/blog/hack-via-pull-request/ https://goteleport.com/blog/hack-via-pull-request/