Skip to content

Comment on Mintlify GitHub read/write token leakparent

Comments

I looked through the git history, but nothing seems awry.

Git history or GitHub event history? You can easily push a malicious commit forged to have the same author and short hash.

Good point. I only looked through the git history initially, but I've now looked through both. Same conclusion.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.