|
|
|
|
|
by sorbits
1907 days ago
|
|
Do I understand correctly that the attacker forks a repository with GitHub Actions enabled, modifies the action, submits a PR, which makes GitHub run the altered action? If so, I wonder if there is a legit need for running modified GitHub actions from non-collaborators? Could also subject modified actions coming in via pull requests (from non-collaborators) to heavy resources constraints and timeouts. |
|
The attack vector in the article is not the main way miners try to steal CPU from the GitHub community. It's just an interesting one that the journalist chose to write about.