CODEDUMP_NOTES Telegram 618
#开源项目
又一种很“新颖”的往开源项目里下毒的手法:有人对Python 包 ultralytics 发了 PR,其中包含如图分支名,当 GitHub 执行 CI 任务时,执行脚本获得仓库密钥,进而在发布包中植入加密货币挖矿程序

https://lwn.net/Articles/1001215/



tgoop.com/codedump_notes/618
Create:
Last Update:

#开源项目
又一种很“新颖”的往开源项目里下毒的手法:有人对Python 包 ultralytics 发了 PR,其中包含如图分支名,当 GitHub 执行 CI 任务时,执行脚本获得仓库密钥,进而在发布包中植入加密货币挖矿程序

https://lwn.net/Articles/1001215/

BY codedump的电报频道




Share with your friend now:
tgoop.com/codedump_notes/618

View MORE
Open in Telegram


Telegram News

Date: |

Unlimited number of subscribers per channel A new window will come up. Enter your channel name and bio. (See the character limits above.) Click “Create.” best-secure-messaging-apps-shutterstock-1892950018.jpg But a Telegram statement also said: "Any requests related to political censorship or limiting human rights such as the rights to free speech or assembly are not and will not be considered." With Bitcoin down 30% in the past week, some crypto traders have taken to Telegram to “voice” their feelings.
from us


Telegram codedump的电报频道
FROM American