GeistHaus
log in · sign up

What the fork? Imposter commits in GitHub Actions and CI/CD

chainguard.dev

Chainguard found a vulnerability in GitHub Actions that bypasses allowed Workflow settings by using commits from forked repositories. Read the report.

10 pages link to this URL
Mini Shai-Hulud Strikes Again: 314 npm Packages Compromised

A compromised npm maintainer account published 631 malicious versions across 314 packages including size-sensor, echarts-for-react, timeago.js, and hundreds of @antv scoped packages, affecting 15M+ monthly downloads.

5 inbound links article en
Fork Commit Detector

Detect potential fork commits (imposter commits) in GitHub repositories. Identify supply chain attack vectors.

1 inbound link website en