Skip to content

Possible Security Breach on Dependabot or Github #81478

Discussion options

You must be logged in to vote

Hi @anilgurses, thanks for posting this!

I appreciate your concern here and hopefully I can reassure you.

It looks like you've subscribed to notifications for PRs on a repository and an account has opened a PR or commented on a thread with off-topic spam. Your email client looks to be threading or grouping these as it's the notifications email address, but it's not all originating from dependabot.

We've seen some abuse like this and our security teams are working hard on stopping this sort of activity in its tracks so that we can keep our users from having to witness content like this. Unfortunately some of it makes it through the notifications system before we get it off the site but we'…

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@anilgurses
Comment options

Answer selected by anilgurses
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment