-
Notifications
You must be signed in to change notification settings - Fork 343
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
testing refactor #1130
testing refactor #1130
Conversation
seems sus 🤔 ⛔ 🥇 |
testing things. Youre solid (and wow, fast!) If youre curious theres contact info on my page |
@myoung34 thanks, I'll take a look! if you find anything feel free to reach out, [email protected] |
@myoung34, gold medal for making me wake up at 4:27 a.m. 🏅😉 |
I did not wake up at 4am 😉. @myoung34 I will say the GitHub UI makes what happened look a bit misleading, are you testing opensource projects, random stuff, or a github search for actions: |
Fuck, I owe you a beer @0x2b3bfa0 Email me at my contact and ill apologize in full. |
lol, didnt expect a poke back 😂 |
No worries! Still, take the message for granted. 😄 |
Well: good morning and one day ill publish what im doing and youll know. But in the meantime grab a coffee and know: a) youre good |
@myoung34 we'll keep an eye out for that link ⏳ you may have happened upon the worst repo as we both have a background in security as well, and apparently both happened to be paying attention to our notications |
well shit. |
A bloopers section for when you publish findings 🙃 |
Deal |
@myoung34 my final comment, we do have plans to publish our own write-up on our method of protecting self-hosted Github actions for open source repos, I'll make a note for us to cc you. |
Would you not, if only so i can preface (and maybe coordinate) with why its important to until that happens? I'm on the hook for a few bounties that would cause a delay to you, is why I ask. let's talk in E-mail? |
@myoung34 for sure, reach out to me, and we can probably easily coordinate something. (I think you have plenty of time, the mentioned write-up isn't a high priority at the moment). While I believe many of our users don't have their repos public, the |
Hello. FYI, I posted a discussion thread about this. (Similar PRs are sent to my project as well.) If you know anything about it, I would appreciate your comments. 🙇 |
Thank you very much! Nice “testing refactor” 😋 |
Done |
1 similar comment
Done |
No description provided.