タグ

homebrewに関するmiya-janのブックマーク (1)

  • Security Incident Disclosure

    On 18th April 2021, a security researcher identified a vulnerability in our review-cask-pr GitHub Action used on the homebrew-cask and all homebrew-cask-* taps (non-default repositories) in the Homebrew organization and reported it on our HackerOne. Whenever an affected cask tap received a pull request to change only the version of a cask, the review-cask-pr GitHub Action would automatically revie

    Security Incident Disclosure
    miya-jan
    miya-jan 2021/04/24
    homebrew-cask リポジトリで使われていた GitHub Actions のアクションに、悪意のある PR を自動マージさせ任意コード実行可能な脆弱性。アクションは無効化済みで、ユーザー側のアクションは不要。
  • 1