Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
elpakal
9 months ago
|
parent
|
context
|
favorite
| on:
How we exploited CodeRabbit: From simple PR to RCE...
So if their GH API token with access to million plus repos was this easy to compromise, isn't it plausible that their token could have been used to clone clone said repos? Is it possible to audit the clone history of a token?
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: