Homebrew fixes Cask repo GitHub Actions bug that would have let anyone sneak malicious code onto machines
Plus: America creates task force to tackle ransomware crims Share Copy In Brief The Homebrew package manager for macOS and Linux has fixed an issue that could have been exploited by miscreants to run malicious code on peoples computers. Specifically, the projects GitHub Actions setup could have been abused to sneak arbitrary Ruby code into its Cask repositories, security researcher RyotaK discovered and disclosed via HackerOne. The infosec bod found it was possible to merge a "malicious...
Source: theregister.com