Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
adnanthekhan
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
adnanthekhan
3y ago
This is more subtle, but there is an “author_association”field within Actions event contexts that can be one of: NONE, CONTRIBUTOR, COLLABORATOR, MEMBER, OWNER There are some cases where people use checks for that as part of gating for work
2.
▲
by
adnanthekhan
3y ago
Yeah, the security posture of that repository is kind of a mess (which is why something like https://adnanthekhan.com/2023/12/20/one-supply-chain-attack-... was even possible in the first place). The balance
3.
▲
by
adnanthekhan
3y ago
Correct. For fork PR workflows on the pull_request trigger the GITHUB_TOKEN has read only permissions, so you can’t do anything with it. The key thing with a non-ephemeral runner is that (after obtaining persistence) you can grab the GITHUB
4.
▲
by
adnanthekhan
3y ago
Oh, you'll like this one then. Until 3 months ago GitHub's Runner images was pulling a package directly from Aliyun's CDN. This was executed during image testing (version check). So anyone with the ability to modify Aliyun&#x
5.
▲
by
adnanthekhan
3y ago
Yup! This is what makes this kind of attack scary and very unique to GitHub Actions. The baseline GITHUB_TOKEN just blows the door open on lateral movement via workflow_dispatch and and repository_dispatch events. In several of our other op