tractus-x: block user who attempts hack via GH actions
Summary
(Summarize the bug encountered concisely)
We noticed some pull requests with some obvious "hacking" attempt (inject commands in our GH workflow runs) last week:
- https://github.com/eclipse-tractusx/portal-backend/pull/1384
- https://github.com/eclipse-tractusx/portal-backend/pull/1385
We reported abuse to Github: https://docs.github.com/en/communities/maintaining-your-safety-on-github/reporting-abuse-or-spam But the user https://github.com/poc455z still doesn't appear to be blocked as a result, at least as far as I can tell.
Could you please block the user https://github.com/poc455z from interacting with our GitHub org? (I think only Org admin can do that)
Apparently there was another PR just today https://github.com/eclipse-tractusx/portal-backend/pull/1388 --> changing therefor the Priority to High
Priority
-
Urgent -
High -
Medium -
Low
Severity
-
Blocker -
Major -
Normal -
Low
Impact
(What is the impact of this issue? Is it blocking a release? Are there any time constraints?, for example: "We have a release tomorrow")