• 52fighters@lemmy.sdf.org
    link
    fedilink
    arrow-up
    25
    ·
    2 days ago

    The article doesn’t say what he did, only that he had write abilities. Did he use them? How do we know? If yes, what were they specifically?

    • draughtcyclist@lemmy.world
      link
      fedilink
      arrow-up
      22
      ·
      2 days ago

      He could push directly to main/prod, so there weren’t explicitly any code reviews or necessarily oversight. Also, that code would be private. Only an insider with repository access could tell us that.

      That said, I also want to know. I’m guessing we’ll hear about it soon enough.

          • Maalus@lemmy.world
            link
            fedilink
            arrow-up
            1
            arrow-down
            8
            ·
            2 days ago

            Not really? Every single maintainer / owner of a repository can do that. The only thing stopping them is protecting a branch. And even that isn’t a thing in git, it’s just something that providers like github or gitlab did to prevent people accidentally pushing to main like that. So they got maintainer access and that’s the entire story?