• azron@lemmy.ml
    link
    fedilink
    English
    arrow-up
    0
    ·
    3 days ago

    Hacked pipeline? These are just pull requests anyone can submit them.

    • BlackEco@lemmy.blackeco.com
      link
      fedilink
      English
      arrow-up
      0
      ·
      edit-2
      3 days ago

      If you watch the PRs history, you can see that the user github-actions edited them. This user is the default one when a GitHub Action (the pipeline OP refers to) alters the repo. So someone probably submitted a pull request abusing the GitHub token when the Action ran on their PR.