Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
securesaml
20 days ago
|
parent
|
context
|
favorite
| on:
Composer leaks contents of tokens configured as Gi...
It's limited to ghs_ (server to server token's), that have the new format enabled:
https://github.blog/changelog/2026-04-24-notice-about-upcomi...
(and actions that use the vulnerable package)
This include's the GITHUB_TOKEN that is builtin within a actions jobs.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search:
This include's the GITHUB_TOKEN that is builtin within a actions jobs.