logoalt Hacker News

ssanderson11235today at 12:12 PM1 replyview on HN

Noone force-pushed to main in the actual repo. The attacker force-pushed to main in their own fork, but the actual repo had a CI job configured that ran code from the fork in response to changes in that fork.


Replies

corvadtoday at 12:39 PM

Ah that makes more sense I was kind of confused by that.