git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFC/PATCH v1] Add Travis CI support

From
Matthieu Moy <matthieu.moy@grenoble-inp.fr>
Date
Oct 5, 2015, 06:54 UTC
Message-ID
<vpq4mi56c12.fsf@grenoble-inp.fr>
In-Reply-To
<1443981968.3520.5.camel@kaarsemaker.net>
Dennis Kaarsemaker <dennis@kaarsemaker.net> writes:
Show 9 quoted lines
> On zo, 2015-10-04 at 10:46 -0700, Junio C Hamano wrote:
>> One final question.  Which configuration file does the CI use when
>> running a PR-initiated test?  The one already in the repository
>> i.e. the target of the proposed pull, or the one that is possibly
>> updated by the PR?
>>
>> I am wondering if that can be an avenue for a possible mischief.
>
> The latter. And it can, as it can enable notifications.

OK, so an attacker can send emails (by faking one of the repository owner's identity on a commit, and then submitting a pull-request for this commit). But such attacker could already send emails via GitHub to all repository watchers (not just owners) by sending pull-requests. Or by using his mailer.

Other than that, Travis-CI uses a container-based infrastructure to ensure clean and independent builds. So, an attacker could trigger a build doing "rm -fr /" or whatever without impacting other builds.

-- 
Matthieu Moy
http://www-verimag.imag.fr/~moy/
Previous: Dennis KaarsemakerNext: Junio C Hamano
Message 22 of 31 in “Add Travis CI support”
  1. Add Travis CI supportlarsxschneider@gmail.com, Sep 24, 2015
  2. Add Travis CI supportlarsxschneider@gmail.com, Sep 24, 2015
  3. Junio C HamanoSep 25, 2015
  4. Dennis KaarsemakerSep 25, 2015
  5. Johannes SchindelinSep 25, 2015
  6. Luke DiamandSep 25, 2015
  7. Junio C HamanoSep 25, 2015
  8. Lars SchneiderSep 26, 2015
  9. Matthieu MoySep 27, 2015
  10. Stefan BellerSep 28, 2015
  11. Matthieu MoySep 28, 2015
  12. Junio C HamanoSep 28, 2015
  13. Matthieu MoySep 28, 2015
  14. Roberto TyleyOct 3, 2015
  15. Junio C HamanoOct 4, 2015
  16. Junio C HamanoOct 4, 2015
  17. Dennis KaarsemakerOct 4, 2015
  18. Johannes SchindelinOct 4, 2015
  19. Matthieu MoyOct 4, 2015
  20. Junio C HamanoOct 4, 2015
  21. Dennis KaarsemakerOct 4, 2015
  22. Matthieu MoyOct 5, 2015
  23. Junio C HamanoOct 5, 2015
  24. Sebastian SchuberthOct 12, 2015
  25. Junio C HamanoOct 4, 2015
  26. Jeff KingOct 4, 2015
  27. Sebastian SchuberthOct 2, 2015
  28. Jeff KingSep 25, 2015
  29. Junio C HamanoSep 25, 2015
  30. Jeff KingSep 25, 2015
  31. Shawn PearceSep 26, 2015

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.