Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mikedd65
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
mikedd65
5y ago
And they did not fix the code of their own runners (like GHA) to check the SHA sum either..
2.
▲
by
mikedd65
5y ago
The e-mail they sent includes "Unfortunately, we can confirm that you were impacted by this security event." which means that they know. I guess there is an API endpoint that is specific to Bash Uploader and they use that + dates
3.
▲
by
mikedd65
5y ago
Can you please tell users which repositories were affected? This situation is ridiculous for users with dozens repositories, using various CIs and various code coverage providers. A lot of checking, cleaning, rotating. The way you disclosed