git-security

2 articles
sort: new top best
clear filter
0 8/10
vulnerability

A researcher discovered that GitHub Actions' use of abbreviated 7-character commit hashes in workflow configs could be exploited to cause global DoS by generating intentional commit hash collisions, which would cause tarball downloads to fail with 404 errors for anyone referencing the ambiguous shorthash. The vulnerability was fixed by updating the config wizard to generate full 40-character commit hashes instead.

GitHub Actions actions/docker 76ff57a 76ff57aa21370794040cd0caafd84d8a7aa0927c
blog.teddykatz.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0 5/10

Betterleaks is a new open-source secrets scanner by Gitleaks' original author that improves detection accuracy using BPE token efficiency (98.6% vs 70.4% entropy recall), CEL-based validation rules, and parallelized scanning. It's designed as a drop-in Gitleaks replacement with support for AI agents and planned features including LLM-assisted classification, auto-revocation, and multi-source scanning.

Betterleaks Gitleaks Zach Rice Aikido Security Richard Gomez Braxton Plaxco Ahrav Dutta Royal Bank of Canada Red Hat Amazon Microsoft Security Response Center CredData dataset CEL (Common Expression Language) BPE tokenization Aikido Safe Chain Aikido Zen Aikido Intel Opengrep
aikido.dev · zricethezav · 1 day ago · details · hn