Skip to content

Commit edd283c

Browse files
haritamarclaude
andauthored
security: remove vulnerable update_pylon_issue.yml workflow (#2206)
This workflow interpolated `${{ github.event.comment.body }}` directly into a `run:` shell step, which allowed any GitHub user to execute arbitrary code on the runner with the workflow's GITHUB_TOKEN by posting a crafted issue/PR comment. That vector was exploited on 2026-04-24 to spoof PRs and publish a malicious package. Removing the workflow entirely (rather than patching) since its only function was auto-flipping a Pylon ticket to "waiting_on_you" on comment, which can be reintroduced safely later via the env-var indirection pattern and an author_association gate. Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
1 parent e5af7e7 commit edd283c

1 file changed

Lines changed: 0 additions & 51 deletions

File tree

.github/workflows/update_pylon_issue.yml

Lines changed: 0 additions & 51 deletions
This file was deleted.

0 commit comments

Comments
 (0)