Demonstrates methods for sneaking malicious code into GitHub pull requests to raise awareness of supply chain vulnerabilities.
A repository demonstrating how you can sneak malicious code into Github PRs
GitHub Actions, even when pinned to a commit SHA, can still pull in malicious code via mutable dependencies like Docker images, unlocked packages, or external scripts
Malicious code can be injected into npm projects via lockfiles (package-lock.json or yarn.lock) because these large, machine-generated files are rarely reviewed thoroughly
Changing account's email to block-listed domain, automatically bans the account
Hidden GitHub comment link
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.