3 ms·
That’s not what happened at all The attacker did not need to merge any PRs to exfiltrate the credentials
by codesparkle 10mo ago
That’s not what happened at all
The attacker did not need to merge any PRs to exfiltrate the credentials
- codesparkle 10mo agoWhat actually happened: The workflow was configured in a way that allowed untrusted code from a branch controlled by the attacker to be executed in the context of a GitHub action workflow that had access to secrets.