GitHub Dataset Research Reveals Millions Potentially Vulnerable to RepoJacking

https://blog.aquasec.com/github-dataset-research-reveals-millions-potentially-vulnerable-to-repojacking

Millions of GitHub repositories are potentially vulnerable to RepoJacking, which if exploited may lead to code execution on environments

2 points · 1 comments · view on lemmy.world

1 Comments

LeberechtReinhold@kbin.social · 2 pts · 3y

I never thought that old organization names became available on Github. After a merge makes sense to keep them locked again or pass ownership to the new owner, not let anyone create that under the old name.

Is there a particular use case it works this way?

That said I doubt this affects millions of orgs, are organization renames that common?