Context

PS: GitHub didn’t like this business strategy that much as they simply deleted that account.

    • jjagaimo@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      15
      ·
      1 day ago

      My understanding is Trivy’s Personal Access Token (PAT) - used for accessing your account via scripts / the services API - got leaked in the repo. The bot saw the PAT and revoked it because someone else could come along and use it to gain access to their repo or impersonate them.

      • FrChazzz@lemmus.org
        link
        fedilink
        English
        arrow-up
        6
        ·
        24 hours ago

        Real June Cleaver “Pardon me, I speak jive” energy coming from this post lol (I mean this as a compliment)

    • Rentlar@lemmy.ca
      link
      fedilink
      arrow-up
      16
      ·
      1 day ago

      I have no idea the context of the situation but this is how I read the post:

      Trivy’s Private Access Token is revoked. The bot was made to autonomously finds exploits and report vulnerabilities but after this situation it intends to cease operation.