Headline
CVE-2023-42798: Release Job Can Reset Git Root Repo to Nothing · Issue #93 · ChewKeanHo/AutomataCI
AutomataCI is a template git repository equipped with a native built-in semi-autonomous CI tools. An issue in versions 1.4.1 and below can let a release job reset the git root repository to the first commit. Version 1.5.0 has a patch for this issue. As a workaround, make sure the PROJECT_PATH_RELEASE
(e.g. releases/
) directory is manually and actually git cloned
properly, making it a different git repostiory from the root git repository.
Skip to content
Actions
Automate any workflow
Packages
Host and manage packages
Security
Find and fix vulnerabilities
Codespaces
Instant dev environments
Copilot
Write better code with AI
Code review
Manage code changes
Issues
Plan and track work
Discussions
Collaborate outside of code
GitHub Sponsors
Fund open source developers
* The ReadME Project
GitHub community articles
- Pricing
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Assignees
Labels
Bug
Case is about a glitch.
Critical
Red alert. High attention needed.
Released
Implementation got released and shipped.
Security
Case is a security vulnerability matter.