Comment by Shank
19 hours ago
I would say, first and foremost, the era where a developer machine with source code access also has access to meaningful security systems should be over. Internal repository access should mean nothing. It's just text files. It does look like this is the case here, where there aren't actually meaningful outcomes from this, but this should be the case everywhere. Isolate these systems from each other. GitHub compromise could happen at any time, even from GitHub themselves.
No comments yet
Contribute on Hacker News ↗