Context

PS: GitHub didn’t like this business strategy that much as they simply deleted that account.

  • LiveLM@lemmy.zip
    link
    fedilink
    English
    arrow-up
    15
    ·
    edit-2
    12 hours ago

    New FOSS attack strategy in which we dismantle projects by making the maintainers die from cringe

  • tiredofsametab@fedia.io
    link
    fedilink
    arrow-up
    7
    ·
    12 hours ago

    I instinctively clicked away at ‘researchmaxxxxed’ (or however many 'x’s the thing had). Do I need to go yell at a cloud now?

    • jjagaimo@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      13
      ·
      12 hours ago

      My understanding is Trivy’s Personal Access Token (PAT) - used for accessing your account via scripts / the services API - got leaked in the repo. The bot saw the PAT and revoked it because someone else could come along and use it to gain access to their repo or impersonate them.

      • FrChazzz@lemmus.org
        link
        fedilink
        English
        arrow-up
        5
        ·
        10 hours ago

        Real June Cleaver “Pardon me, I speak jive” energy coming from this post lol (I mean this as a compliment)

    • Rentlar@lemmy.ca
      link
      fedilink
      arrow-up
      16
      ·
      16 hours ago

      I have no idea the context of the situation but this is how I read the post:

      Trivy’s Private Access Token is revoked. The bot was made to autonomously finds exploits and report vulnerabilities but after this situation it intends to cease operation.

    • communism@lemmy.ml
      link
      fedilink
      arrow-up
      8
      arrow-down
      1
      ·
      10 hours ago

      This isn’t gen Z slang. It’s largely butchered AAVE (which is an entirely valid dialect with its own internally consistent grammar and vocabulary). Many such cases.