Comment by KingOfCoders
Comment by KingOfCoders 6 days ago
Did I misread the article, or did they take the tool config from the PR not the repo?
Comment by KingOfCoders 6 days ago
Did I misread the article, or did they take the tool config from the PR not the repo?
The exploit depends on changing the config to execute a .rb file. And the config was supplied by a PR.
Unfortunately that mostly has to be the case or else the developer experience configuring these would be too bad.