New audit: repojacking #479
Labels
enhancement
New feature or request
good first issue
Good for newcomers
help wanted
Extra attention is needed
new-audit
New audits
We should flag
uses: foo/bar
iffoo
is not a valid GitHub user/org/etc. In some cases (iffoo/bar
was not already a sufficiently popular repository, an attacker can create thefoo
user andbar
repository).GitHub now has stronger repository "retirement" protections, so this is not always exploitable.
The text was updated successfully, but these errors were encountered: