Parodia
  • Communities
  • Multi-communities
  • Support Lemmy
  • Search
  • Login
  • Sign Up
Linux@lemmy.mlbyDymonika@lemmy.ml
2 months

See? I TOLD you all to leave GitHub! "Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks"

thehackernews.com

Don’t say I didn’t warn you…

6
    Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks
    thehackernews.com
    Researchers found Cordyceps CI/CD flaws affecting 300+ repositories, enabling code execution, credential theft, and supply chain risks.
    You must log in or register to comment.

    • minfapper@piefed.socialEnglish
      2 months

      The core of the problem trickles down to weak CI/CD configurations that grant pull requests (PRs) more permissions than they should have.

      How exactly do their competitors like codeberg do better in preventing that?

        • onlinepersona@programming.dev
          2 months

          The article doesn’t seem to say. I don’t know if it’s a problem with defaults or caused by the devs themselves.

            • minfapper@piefed.socialEnglish
              2 months

              By default pull requests my new contributors require approval from someone with write-access to the repo before running actions.

              These repos have specifically decided to change a setting to make them not require approval for anyone. The UI to change that setting explicitly warns you about exactly this attack, so this “article” feels like a non-item trying to farm engagement.

              • real_username56@lemmy.mlEnglish
                2 months

                As far as I can tell it requires GitHub actions to be enabled for pull requests, which you can require approval for. I just quickly read the top of the article so I could be wrong

              • A_norny_mousse@piefed.zipEnglish
                2 months

                I’m no expert in this but I’m guessing GH’s higher tiers provide much more “actions” and whatnot than Codeberg does. AFAICS Gitlab might be the only alternative that even has the mechanisms that could be exploited.

                But executing code in a comment, that’s harsh in any case. I mean, even I would’ve known how to prevent that right from the start. I think.

              • A_norny_mousse@piefed.zipEnglish
                2 months

                That sounds big & creepy:

                On Microsoft’s Azure Sentinel, for example, Novee found a comment on a PR that could run anonymous attacker code on Microsoft’s CI and steal a non-expiring GitHub App key.

                I wonder if/how alternative VCS platforms that provide similar workflow services are affected.

                Linux@lemmy.ml

                linux@lemmy.ml

                Subscribe from remote instance

                Create post

                Report community

                Modlog
                You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !linux@lemmy.ml

                From Wikipedia, the free encyclopedia

                Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).

                Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word “Linux” in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.

                Rules

                • Posts must be relevant to operating systems running the Linux kernel. GNU/Linux or otherwise.
                • No misinformation
                • No NSFW content
                • No hate speech, bigotry, etc

                Related Communities

                • !opensource@lemmy.ml
                • !libre_culture@lemmy.ml
                • !technology@lemmy.ml
                • !libre_hardware@lemmy.ml

                Community icon by Alpár-Etele Méder, licensed under CC BY 3.0

                Visibility: Public

                This community is visible to everyone.

                • 849 users / Day
                • 3.08K users / Week
                • 5.42K users / Month
                • 6.76K users / 6 months
                • 556 posts
                • 6.88K comments
                • 1 local subscriber
                • 67.2K subscribers
                • BE: 1.0.0-beta.1
                • Modlog
                • Legal
                • Instances
                • Docs
                • Code
                • join-lemmy.org