Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm extremely surprised as well. This seems like a obvious vector for an impersonation attack. A malicious user could do this, then perhaps they would have more success submitting a malicious change to "correct a flaw in their previous commit"

At the very least, repo owners should have some better control over how attributions display when the user is not a project member or the email used is not verified to an existing user.



Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: