Giteabot account was compromised
github.com
Giteabot account was compromised
1–10 of 66 posts
Re: Giteabot account was compromised
#2Re: Giteabot account was compromised
#3Has anyone taken a look at the binaries themselves to see what they do and how they differ from the official releases?
Re: Giteabot account was compromised
#4Re: Giteabot account was compromised
#5Good thing on them being open about it though, despite it probably costing them some potential traction.
Re: Giteabot account was compromised
#6Re: Giteabot account was compromised
#7Funny to see this news posted on github , after people having suggested gitea as a viable platform to migrate your github projects to ever since the MS buyout. Good thing on them being open about it though, despite it probably costing them some potential traction.
Re: Giteabot account was compromised
#8Funny to see this news posted on github , after people having suggested gitea as a viable platform to migrate your github projects to ever since the MS buyout. Good thing on them being open about it though, despite it probably costing them some potential traction.
Probably a bit of exaggeration there, but there's a good chance that whatever was used to exploit Gitea has been there for quite a long time. A leaked personal access token for the bot account that was there for the taking all the time, if someone cared to scan their CI logs. Something like that.
Re: Giteabot account was compromised
#9Funny to see this news posted on github , after people having suggested gitea as a viable platform to migrate your github projects to ever since the MS buyout. Good thing on them being open about it though, despite it probably costing them some potential traction.
Many projects are ironically this way. Gitea, gogs, yunohost, sandstorm to name a few.