Get the latest tech news

Abusing Git branch names to compromise a PyPI package


d release was uploaded to PyPI after a project automatically processed a pull request with a flawed script. The GitHub account "OpenIM Robot" (which appears to be controlled by Xinwei Xiong) opened a pull request for the ultralytics Python package.

[Posted December 6, 2024 by daroc]

Get the Android app

Or read this on Hacker News

Read more on:

Photo of PyPI

PyPI

Photo of Git

Git

Photo of PyPi package

PyPi package

Related news:

News photo

Git-crypt – transparent file encryption in Git

News photo

How I configure my Git identities

News photo

Show HN: Fireproof – local-first database with Git-like encrypted sync