Ranter
Join devRant
Do all the things like
++ or -- rants, post your own rants, comment on others' rants and build your customized dev avatar
Sign Up
Pipeless API
From the creators of devRant, Pipeless lets you power real-time personalized recommendations and activity feeds using a simple API
Learn More
Comments
-
Looks like a malfunction - doesn't make sense for a bot to spam a single repo as it increases the likelyhood of sleepy maintainers getting that something is wrong about those pull requests.
-
@Oktokolo My mistake, it made prs on different repos with pom and makefile updates, sending the output of set to a random server. The title mentioned a bug bounty, so it's fishing for that
-
@alexbrooklyn That's odd. Mentioning wanting money for the fix makes maintainers hunt extra hard for reasons not to accept the pull request.
-
@Oktokolo they don't want the pr to be accepted, they want to find holes in whatever ci/cd system is running the pipeline for the pull request
-
@alexbrooklyn okay, that makes sense. Well, at least scripting languages always come with automatic memory management - so the most common RCE vectors are already closed...
A bot just made 519 pull requests with malicious Makefile code to get a github actions server to send a curl to a random host.
It's gonna be one of those days
rant