Earlier quoted context omitted.
The "attack" clearly wasn't malicious, though probably immature. A malicious attacker would have been doing things like gaining access to users' private repos and stealing the code, or trying to sneak in harmful commits to a repo under a false name. This was at most a prank or a demonstration. So why this instead of responsible disclosure? The problem is that it was not really a GitHub issue, it's Rails having a gros…
This clearly was malicious: * it provides a how to for other individuals to repeat the attack, in a public forum. * it was made against an innocent third-party. * I doubt steps were taken to contact the third-party. * it was made on a Sunday morning. making it difficult to scramble and get a fix out the door. "Clearly the Rails core team were not willing to consider any kind of changes to improve the situation" The t…
I already agreed that GitHub were innocent bystanders and that the timing was unfortunate. But if getting publicity to the issue was the main point, it's also easy to see why GitHub was the perfect target. I also already explained why it could make perfect sense to demonstrate the vulnerability in a public manner rather than just disclose it to one of the many sites suffering from the problem. None of that is a sign of malice, it's at most bad judgement.
The ticket having been opened only three days ago would be a good point if it hadn't also been closed and declared to be working as intended with a pointer to a previously closed bug about the same issue.