Skip to content

Comment on Upptime – GitHub-powered open-source uptime monitor and status page

Comments

@anandchowdhary Can you explain the security implications of using Upptime?

Does it need a token to access all of the user's GitHub repos?

That's a little worrying because the code does not reside in the git repo it's fetched from third-party repos by the GitHub Action. Does this mean the user has no way of auditing and locking down the code to prevent future compromises to third-party repos?

If yes, then an attacker that compromises Upptime or one of the third-party GitHub Actions could hijack all of the users repos (including non-Upptime repos owned by the users).

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.