Skip to content
TopicTracker
From HackerNewsView original
TranslationTranslation

We got attacked via GitHub PRs

The company Blef experienced a security incident where an attacker submitted malicious GitHub pull requests to their open-source repositories. The attack exploited CI/CD pipelines to attempt unauthorized access, highlighting the risks of accepting unsolicited contributions without proper security checks.

Related stories