You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
When /ok-to-test is remembered, it is possible for an external contributor to gain trust with a reasonable code change and then push a malicious change which is targeted at the build system (i.e. secret exfiltration).
In order to mitigate this risk, PAC should configure this to false by default and documentation should be added to highlight the risk. Installations would then have to explicitly set this to true to accept the potential risk of the configuration.
The text was updated successfully, but these errors were encountered:
When
/ok-to-test
is remembered, it is possible for an external contributor to gain trust with a reasonable code change and then push a malicious change which is targeted at the build system (i.e. secret exfiltration).In order to mitigate this risk, PAC should configure this to
false
by default and documentation should be added to highlight the risk. Installations would then have to explicitly set this totrue
to accept the potential risk of the configuration.The text was updated successfully, but these errors were encountered: