Tell HN: Travis CI is seemingly compromised (once again)
Travis themselves have still not issued any notice or acknowledged this incident so it's worth letting the community know if they weren't already aware.
From memory, this will be the second breach in 2022 (https://blog.aquasec.com/travis-ci-security) in addition to last year's secret exposure (https://arstechnica.com/information-technology/2021/09/travi...)
---
A sampling of users on Twitter who have run into this issue:
https://twitter.com/peter_szilagyi/status/160059327410805555...
https://twitter.com/yaqwsx_cz/status/1600599797118996491
https://twitter.com/samonchain/status/1600611567606775808
https://twitter.com/dzarda_cz/status/1600613369408634886
https://twitter.com/samonchain/status/1600611567606775808
---
An example notice being sent out by Github (in lieu of Travis themselves taking any action):
> Hi {username}
> We're writing to let you know that we observed suspicious activity that suggests a threat actor used a Personal Access Token (PAT) associated with your account to access private repository metadata.
> Out of an abundance of caution, we reset your account password and revoked all of your Personal Access Tokens (classic), OAuth App tokens, and GitHub App tokens to protect your account, {username}.
[+] [-] stuaxo|3 years ago|reply
[+] [-] rattlesnakedave|3 years ago|reply
[+] [-] jahnu|3 years ago|reply
[+] [-] stronglikedan|3 years ago|reply
[+] [-] transcriptase|3 years ago|reply
[+] [-] piskerpan|3 years ago|reply
[+] [-] fmajid|3 years ago|reply
[+] [-] p0nce|3 years ago|reply
[+] [-] nailer|3 years ago|reply
[+] [-] mjlawson|3 years ago|reply
[+] [-] NuMessiah|3 years ago|reply
[+] [-] ethbr0|3 years ago|reply
[+] [-] josteink|3 years ago|reply
After they did organizational changes, and some other stuff, I noticed my builds were hardly running. Many never started, and ever more never completed.
Travis was causing more issues than it solved for my projects' Github PRs.
I'm honestly surprised to see people still using Travis now, a few years down the line.
[+] [-] sensitivefrost|3 years ago|reply
[+] [-] ransom1538|3 years ago|reply
[+] [-] jesuspiece|3 years ago|reply
[+] [-] barbazoo|3 years ago|reply
[+] [-] shp0ngle|3 years ago|reply
edit: ah no, only some
[+] [-] Throwawayaerlei|3 years ago|reply
"Because that's where the money is" frequently works, even if the quote is apocryphal.
[+] [-] hdjjhhvvhga|3 years ago|reply
[+] [-] djbusby|3 years ago|reply
Migrating was tedious, not difficult. We went slow, took a while and needed little scaffolding
[+] [-] jghn|3 years ago|reply
[+] [-] nstart|3 years ago|reply
[+] [-] unknown|3 years ago|reply
[deleted]
[+] [-] zaps|3 years ago|reply