logoalt Hacker News

Composer leaks contents of tokens configured as GitHub OAuth tokens

56 pointsby damienwebdevtoday at 11:26 AM23 commentsview on HN

Comments

damienwebdevtoday at 11:26 AM

I was the reporter on this one. If you have Github Actions in your organization, disable them immediately if you're unsure which version of composer your Github Actions run.

show 3 replies
Normal_gaussiantoday at 7:27 PM

GHA have always been a PITA for any serious DevOps; it's quite clear they were designed to integrate in 7 lines of code and then tell everyone who complains that they're doing it wrong.

This does not surprise me.

show 2 replies
ShowalkKamatoday at 9:19 PM

I may be silly but why would you ever want to validate the structure of an opaque authentication key? Couldn't you just hit an harmless endpoint (e.g. /rate_limit) to see if it returns 401 or not?

euph0riatoday at 8:06 PM

What is the security implication for private repos?

show 1 reply
esafaktoday at 7:33 PM

The title suggests it is a Github issue but really it is https://github.com/composer/composer no? I would edit the title for clarity.

show 2 replies
h1fratoday at 8:31 PM

the title is incorrect; it's not a github error but php composer's github action. cc @dang before people freak out

show 1 reply