Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

As the runner process parses every line printed to STDOUT looking for workflow commands, every Github action that prints untrusted content as part of its execution is vulnerable.

What could possibly go wrong?



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: