logoalt Hacker News

themlyyesterday at 9:43 PM2 repliesview on HN

Long story short: they messed up the assign-reviewers.yml workflow, allowing external contributors to merge PRs without proper reviews. From this point on, you're fully open to all kinds of bad stuff.


Replies

ivanjermakovyesterday at 11:36 PM

Opener source software

vanschelvenyesterday at 10:19 PM

more so in case you actually do the "secrets on github with the right to do meaningful things"

show 1 reply