• azron@lemmy.ml
    link
    fedilink
    English
    arrow-up
    23
    arrow-down
    4
    ·
    3 days ago

    Hacked pipeline? These are just pull requests anyone can submit them.

    • itsathursday@lemmy.world
      link
      fedilink
      English
      arrow-up
      34
      ·
      3 days ago

      They are authentic commits and PRs by real contributors that have been edited and renamed with the PR description changed.

      • azron@lemmy.ml
        link
        fedilink
        English
        arrow-up
        7
        ·
        3 days ago

        Oh that is mildly interesting, my mistake. So the actual commits didn’t change but the pull requests are made to look like they are something else.

        • r00ty@kbin.life
          link
          fedilink
          arrow-up
          3
          ·
          3 days ago

          I think the top one might be the culprit. But it might be the guy’s account was hacked?

          On his repo he has a fork of WSL and the repo is called “free-palestine”, he tried to merge the branch “freedom”. So that PR seems likely to be linked to this. Other than this, activity seems normal for a terminal githubber with 444 repos…