logoalt Hacker News

t0mas88last Sunday at 3:44 PM2 repliesview on HN

But the attacker could just create a branch, merge request and then merge that?


Replies

benoaulast Sunday at 5:51 PM

They can't with git by itself, but if you're also signed in to GitHub or BitBucket's CLI with an account able to approve merges they could use those tools.

x0x0last Sunday at 6:52 PM

We require review on PRs before they can be merged.