Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mgiladi
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
15 ms
·
1.
▲
by
mgiladi
2y ago
They have no way of knowing unless they have admin access, in which case they can do whatever they want anyway. If the tool produces any visible outputs, just configure it to block silently. That's on the maintainer side. On the consum
2.
▲
by
mgiladi
2y ago
We've recently released open-source tools that would have easily prevented this, before anything runs or added to any pipeline: 1. The maintainers could have used PRevent to immediately alert and block any PR containing malicious code,
3.
▲
by
mgiladi
2y ago
We've recently released open-source tools that would have easily prevented this: 1. The maintainers could have used PRevent to immediately alert and block any PR containing malicious code, or easily configured it for detection in case
4.
▲
Show HN: I built a PR listener and ruleset to detect malicious code in CI/CD
(github.com)
13 points
by
mgiladi
2y ago
|
1 comments
5.
▲
Show HN: Malicious code detector
(github.com)
4 points
by
mgiladi
2y ago
|
0 comments