GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    Tanawts (enigma@infosec.exchange)'s status on Wednesday, 19-Mar-2025 14:49:54 JSTTanawtsTanawts
    • Kevin Beaumont

    @GossiTheDog am i tripping? Who watches the watchers?

    https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised

    Github seems to only have logs for the git protocol usage itself, but I dont seem to see logs for interactions like views on the www.github.com web portal itself, eg. for things like who logged in to the web portal and viewed workflow logs that would contain base64 double encoded passwords.

    Bing/CoPilot has an unsatisfactory answer as well:

    "How do I audit github for people who looked at github workflow logs

    Unfortunately, GitHub doesn't provide a straightforward way to see who has viewed workflow logs. Logs are generally accessible to anyone with sufficient permissions in a repository, but GitHub doesn't track or display individual views on these logs."

    I don't think github logs access to github
    I think github logs access to git

    In conversationabout 2 months ago from infosec.exchangepermalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: github.githubassets.com
      GitHub: Where the world builds software
      GitHub is where over 83 million developers shape the future of software, together. Contribute to the open source community, manage your Git repositories, review code like a pro, track bugs and feat...
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.