logoalt Hacker News

someonebaggy • today at 4:11 AM • 0 replies • view on HN

You could pull a malicious colliding PR and reject it. Then you pull the other half of the collision without realising it is, and it's something good and you merge it. But your CI server already saw the malicious one and thinks it's the same, so builds the malicious code