GitHub’s Confidential Advisory Comments Follow Repository Write Access

Confidential comments follow repository permissions.

Confidential comments follow repository permissions.

Provenance answered where the package was built. It could not answer whether the source reaching the trusted workflow was honest.

The upload bug lived in a third-party forum. The blast radius grew because a community sign-in token carried access into employee AI accounts and GitHub.
The employee had left. The token had not. GitHub traced the access path back to the wider TanStack supply-chain incident.
The repositories copied more than 40 brands. The payload then used a trusted driver to remove the tools most likely to stop it.

A new Shai-Hulud descendant spread through npm packages with legitimate-looking provenance. The incident shows why a trusted build path is not necessarily a trustworthy one. Security researchers identified a fast-moving npm supply-chain campaign on 4 August and named it ChainDrop.…

A malicious notebook could turn github.dev into a GitHub OAuth-token theft path with read and write access across the developer's repositories.

A compromised Nx Console update reached a GitHub employee device, stole credentials, and exposed roughly 3,800 internal repositories.