Y
Hacker News
new
|
ask
|
show
|
jobs
by
KingOfCoders
298 days ago
Did I misread the article, or did they take the tool config from the PR not the repo?
2 comments
yxhuvud
298 days ago
Unfortunately that mostly has to be the case or else the developer experience configuring these would be too bad.
link
morgante
298 days ago
The exploit is there either way.
link
KingOfCoders
298 days ago
The exploit depends on changing the config to execute a .rb file. And the config was supplied by a PR.
link
flexagoon
298 days ago
Yes, but the exploit grants you access to ALL repos, not just the one the PR is in. You could just as well change the config in your own private repo and run coderabbit in it.
link