/PRNewswire/ Synopsys, Inc. (Nasdaq: SNPS) today announced the expansion of the Technology Alliance Partner (TAP) segment of the Software Integrity Group s.
GitHub Actions Down | Hacker News ycombinator.com - get the latest breaking news, showbiz & celebrity photos, sport news & rumours, viral videos and top stories from ycombinator.com Daily Mail and Mail on Sunday newspapers.
Red Hat unveils Developer Sandbox for OpenShift to power Kubernetes app development
SHARE
The OpenShift sandbox is a private environment in a shared, multitenant cluster already configured with a set of developer tools, so that the preparation is done before the developers “walk” into the environment. Rather like a virtual garage, it’s set up with everything they need.
Developers can get started right away by putting together Kubernetes applications using the same infrastructure and tools that would run in production environments – without the need to worry about production hardware and no risk of breaking anything anyone can see.
Plus, since it’s all virtualized, the sandbox allows them to save states, freeze them, set them aside for later and restore them as desired. It’s even possible to destroy everything and start from a clean slate whenever needed.
Codecov s Bash Uploader script could be verified to check for tampering via a cryptographic checksum, but despite this it was a couple of months before the compromise was detected. The use of the script within GitHub actions was one example where the checksum was not inspected.
Following the security incident, GitHub users raised an issue, Checksum should be run on bash uploader script before execution, with one developer remarking that the idea to directly and blindly execute a bash script pulled from the web is a giant security hole and a ticking bomb for future breaches.
Codecov attempted to add verification to the GitHub Action which then started raising false positives thanks to a mismatch between the checksum and the script actually in use. This is the kind of friction which undermines efforts to improve security.