3 ms·
Someone has maintainer/admin access to the repository and has force-pushed to master overwriting the git history. Notice that the original commit is verified:
by RVuRnvbM2e 7mo ago
Someone has maintainer/admin access to the repository and has force-pushed to master overwriting the git history.
Notice that the original commit is verified: https://github.com/pedronauck/reworm/commit/df8c1803c519f599c3b61abd6613c0f98ab44fa4 https://github.com/pedronauck/reworm/commit/df8c1803c519f599...
While the malicious one is not: https://github.com/pedronauck/reworm/commit/d50cd8c8966893c6269153a3c093c801fd62ba16 https://github.com/pedronauck/reworm/commit/d50cd8c8966893c6...
- globular-toast 7mo agoThis reveals a deeper flaw in the whole git/npm pipeline (would apply to other systems like PyPI etc, not npm exclusively). These systems should operate on a "pull" model, not a push. The system should have rejected a build that wasn't derived from the latest in its repository. It would be quite easy in concept to set up one's own system to pull every source on npm and alert when the upstream has deviated.
- redman25 7mo agoSo someone is debugging something with git bisect and stumbles on the old commit and gets pwned. Maybe that's why they force killed it? To avoid people going back in history and stumbling on it.