Skip to content

hackeriet/attacker

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

1 Commit
 
 
 
 
 
 
 
 

Repository files navigation

reviewdog-poc-victim

Private PoC reproducing the pull_request_target + go generate sink pattern observed in sealdice/sealdice-core and sealdice/sealdice-ui.

Vulnerable workflow at .github/workflows/reviewdog.yml is a verbatim copy of the upstream pattern. Test method: open a cross-fork PR from hackeriet/reviewdog-poc-attacker carrying a benign //go:generate directive and confirm execution in the workflow logs.

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors

Languages

  • Go 100.0%