Re: Changes to Git commit workflow

From: Date: Mon, 29 Mar 2021 21:32:16 +0000
Subject: Re: Changes to Git commit workflow
References: 1 2  Groups: php.doc php.internals php.internals 
Request: Send a blank email to internals+get-113856@lists.php.net to get a copy of this message
Den 2021-03-29 kl. 23:10, skrev Benjamin Morel:
Hi everyone, Yesterday (2021-03-28) two malicious commits were pushed to the php-src repo [1] from the names of Rasmus Lerdorf and myself. We don't yet know how exactly this happened, but everything points towards a compromise of the git.php.net server (rather than a compromise of an individual git account).
That is scary. Can you disclose the contents of the commits? Are they specially designed to open a security hole, or to be harmful in another way? An article from The Hacker News and a tweet from Zerodium about the incident:
-https://thehackernews.com/2021/03/phps-git-server-hacked-to-insert-secret.html -https://twitter.com/cBekrar/status/1376469666084757506 r//Björn L

Thread (45 messages)

« previous php.internals (#113856) next »