Force user to reauthenticate (sudo mode) to create/edit a release #202353
Replies: 1 comment
-
|
💬 Your Product Feedback Has Been Submitted 🎉 Thank you for taking the time to share your insights with us! Your feedback is invaluable as we build a better GitHub experience for all our users. Here's what you can expect moving forward ⏩
Where to look to see what's shipping 👀
What you can do in the meantime 💻
As a member of the GitHub community, your participation is essential. While we can't promise that every suggestion will be implemented, we want to emphasize that your feedback is instrumental in guiding our decisions and priorities. Thank you once again for your contribution to making GitHub even better! We're grateful for your ongoing support and collaboration in shaping the future of our platform. ⭐ |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
🏷️ Discussion Type
Product Feedback
💬 Feature/Topic Area
Supply chain security
Discussion Details
It would be nice to have a repository feature to force a repository's maintainer to re-authenticate themselves (e.g. sudo mode) before creating or editing a release (or toggling that parameter off !). This would prevent an attacker hijacking a maintainer's account from creating a new release with malicious code (and since publishing to other platforms is usually handled by CI, to publish that malicious artifact to other platforms).
I know editing releases is already covered by immutable releases, but I think this is only a partial protection because the setting can be disabled without re-auth, and doesn't cover creating new releases anyway.
this feature would be greatly appreciated. Here is one such project that would greatly benefit from this feature if you need more info about a use case: https://github.com/WerWolv/ImHex
Beta Was this translation helpful? Give feedback.
All reactions