Re: ISC, GitHub, and CVE-2025-30066

2025-04-05 Thread John Thurston
Thank you for the clear and concise explanation. -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska On 3/20/2025 8:42 AM, Ondřej Surý wrote: On 20. 3. 2025, at 23:12, John Thurston wrot

Re: ISC, GitHub, and CVE-2025-30066

2025-03-20 Thread Ondřej Surý
> On 20. 3. 2025, at 23:12, John Thurston wrote: > > And since I know that ISC has projects at GitHub, and I suspect that ISC > projects would be a big, fat, juicy target for code injection, I feel like I > gotta ask . . Is ISC willing to weigh in and say if their projects may have > been aff

ISC, GitHub, and CVE-2025-30066

2025-03-20 Thread John Thurston
I was reading about CVE-2025-30066. I must admit that my git-knowledge is close to nil, but if I'm reading the description right then this CVE is describing a pathway which let bad-actors potentially gain keys to other projects in GitHub. Projects that used the compromised version of *tj-acti