Securing the Git push pipeline: Responding to a critical remote code execution

samtrack2019 14 points 2 comments April 28, 2026
github.blog · View on Hacker News

Discussion Highlights (2 comments)

time4tea

I mean, sure. But what about allowing user inputs in trusted fields, Or allowing switching environments per request, on inputs from users Or allowing requests in a user context to access storage from another Or storing everything in plaintext on a node that everything can access Or not validating user inputs Or... Its not a success story.

philipwhiuk

Nothing on auditing other fields? Nothing on how it escaped test coverage? No fuzzing?

Semantic search powered by Rivestack pgvector
8,303 stories · 78,303 chunks indexed