Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
undefined | Better HN
0 points
morgante
7mo ago
0 comments
Share
The exploit is there either way.
0 comments
default
newest
oldest
KingOfCoders
7mo ago
The exploit depends on changing the config to execute a .rb file. And the config was supplied by a PR.
flexagoon
7mo ago
Yes, but the exploit grants you access to ALL repos, not just the one the PR is in. You could just as well change the config in your own private repo and run coderabbit in it.
j
/
k
navigate · click thread line to collapse