Context

PS: GitHub didn’t like this business strategy that much as they simply deleted that account.

  • jjagaimo@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    15
    ·
    1 day ago

    My understanding is Trivy’s Personal Access Token (PAT) - used for accessing your account via scripts / the services API - got leaked in the repo. The bot saw the PAT and revoked it because someone else could come along and use it to gain access to their repo or impersonate them.

    • FrChazzz@lemmus.org
      link
      fedilink
      English
      arrow-up
      6
      ·
      1 day ago

      Real June Cleaver “Pardon me, I speak jive” energy coming from this post lol (I mean this as a compliment)