| github | https://github.com/kpcyrd/sn0int |
| docs | https://sn0int.readthedocs.io/ |
| irc | irc.hackint.org:6697/#sn0int |
| github | https://github.com/kpcyrd/sn0int |
| docs | https://sn0int.readthedocs.io/ |
| irc | irc.hackint.org:6697/#sn0int |
How to landmine an org that uses the gitlab package registry:
The gitlab options {maven,npm,pypi}_package_requests_forwarding all default to on. If you register the org's pkgs on the public registry, their gitlab is going to serve your code if they ever delete their private pkg.
Stay tuned in 2023 for offensive supply-chain security https://github.com/kpcyrd/sh4d0wup ๐ฆ
QT kpcyrd: The hardest part of writing a malicious container registry is how fragmented the ecosystem is. Each of these are valid responses when pulling a specific container image by tag.
@[email protected] Will IA be scraping and archiving peoples' toots without their knowledge and/or consent? @[email protected]
Dear doordash engineers, it could be worse: at least you're not asked to be an opensource worker
QT kpcyrd: Since people are tweeting about delivery workers right now: this is how much I made last month delivering food 2 days a week on minimum wage vs how much I made working on opensource 7 days a week (and I'm already blessed it's that high ๐)