Hacker News new | past | comments | ask | show | jobs | submit login

Not the first time this particular action has had a vulnerability, either.

https://nvd.nist.gov/vuln/detail/CVE-2023-51664




I could have sworn that I've seen other GitHub Actions vulnerabilities that worked the same way, too. And/or HN submissions talking about this specific kind of vulnerability, the standard mitigation strategies, etc.

Feels like the same kind of problem as SQL injection, where everybody kinda knows about it and some people are actively aware and there are standard ways to avoid it but it still happens all the time anyway.

Might also be a good time to mention I'm really not a fan of YAML.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: