Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

With Bitbucket, as well as Gitlab and likely others that I haven't used, the CI pipelines are stored as a plaintext configuration in the repo itself. So, repo commit access automatically gives you the ability to modify the pipeline.


This is why things like codeowners files are so important




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: