public inbox for gentoo-announce@lists.gentoo.org
 help / color / mirror / Atom feed
Search results ordered by [date|relevance]  view[summary|nested|Atom feed]
thread overview below | download: 
* [gentoo-announce] Re: Gentoo Github Organization hacked.
  @ 2018-07-04 14:53 99% ` Alec Warner
  0 siblings, 0 replies; 1+ results
From: Alec Warner @ 2018-07-04 14:53 UTC (permalink / raw
  To: gentoo-announce, gentoo-user

[-- Attachment #1: Type: text/plain, Size: 1221 bytes --]

We believe this incident to be resolved and we have written an incident
report:

https://wiki.gentoo.org/wiki/Github/2018-06-28

Thanks to the community for their support during this incident.

-A

On Thu, Jun 28, 2018 at 5:13 PM, Alec Warner <antarus@gentoo.org> wrote:

> Today 28 June at approximately 20:20 UTC unknown individuals have gained
> control of the Github Gentoo organization, and modified the content of
> repositories as well as pages there. We are still working to determine the
> exact extent and to regain control of the organization and its
> repositories.
>
> All Gentoo code hosted on github should for the moment be considered
> compromised. This does NOT affect any code hosted on the Gentoo
> infrastructure. Since the master Gentoo ebuild repository is hosted on our
> own infrastructure and since Github is only a mirror for it, you are fine
> as long as you are using rsync or webrsync from gentoo.org.
>
> Also, the gentoo-mirror repositories including metadata are hosted under a
> separate Github organization and likely not affected as well.
>
> All Gentoo commits are signed, and you should verify the integrity of the
> signatures when using git.
>
> More updates will follow.
>
> -A
>

[-- Attachment #2: Type: text/html, Size: 1840 bytes --]

^ permalink raw reply	[relevance 99%]

Results 1-1 of 1 | reverse | options above
-- pct% links below jump to the message on this page, permalinks otherwise --
2018-06-28 21:13     [gentoo-announce] Gentoo Github Organization hacked Alec Warner
2018-07-04 14:53 99% ` [gentoo-announce] " Alec Warner

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox