|
|
|
|
|
by chatmasta
1902 days ago
|
|
> Getting a hold of someone's secrets is not possible just by doing a pull request Only if you've configured the actions correctly. I would bet that there is a high number of repositories on both GitLab and GitHub with misconfigured CI pipelines where someone can submit a PR with `env | curl` to grab any secrets defined as environment variables. |
|