logoalt Hacker News

rawgabbittoday at 3:41 PM1 replyview on HN

Help me understand. Snowflake configured their Github repo to allow auto fixes by Copilot. It got merged automatically without anyone's review? And introduced essentially script-injection vulnerability through the title field?

If this is the case, I would say Snowflake should shut down its repo and get off Github asap.


Replies

raframtoday at 4:08 PM

No. A Snowflake maintainer opened a PR, Copilot suggested a change (introducing a vulnerability), the maintainer accepted and committed it to their PR, and another Snowflake maintainer approved and merged the PR.

show 2 replies