public inbox for gentoo-dev-announce@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-dev-announce] Re: Gentoo Github Organization hacked.
       [not found] <CAAr7Pr9ijQMFE5U28p4M0H6Y+LKN5WRpzM_LAGq90juwuNsArw@mail.gmail.com>
@ 2018-06-28 22:24 ` Robin H. Johnson
  0 siblings, 0 replies; only message in thread
From: Robin H. Johnson @ 2018-06-28 22:24 UTC (permalink / raw
  To: gentoo-dev-announce

[-- Attachment #1: Type: text/plain, Size: 1355 bytes --]

(gentoo-dev-announce was missed in the initial email blast. Incident
response is ongoing).

On Thu, Jun 28, 2018 at 05:13:18PM -0400, Alec Warner wrote:
> Today 28 June at approximately 20:20 UTC unknown individuals have gained
> control of the Github Gentoo organization, and modified the content of
> repositories as well as pages there. We are still working to determine the
> exact extent and to regain control of the organization and its
> repositories.
> 
> All Gentoo code hosted on github should for the moment be considered
> compromised. This does NOT affect any code hosted on the Gentoo
> infrastructure. Since the master Gentoo ebuild repository is hosted on our
> own infrastructure and since Github is only a mirror for it, you are fine
> as long as you are using rsync or webrsync from gentoo.org.
> 
> Also, the gentoo-mirror repositories including metadata are hosted under a
> separate Github organization and likely not affected as well.
> 
> All Gentoo commits are signed, and you should verify the integrity of the
> signatures when using git.
> 
> More updates will follow.
> 
> -A

-- 
Robin Hugh Johnson
Gentoo Linux: Dev, Infra Lead, Foundation Treasurer
E-Mail   : robbat2@gentoo.org
GnuPG FP : 11ACBA4F 4778E3F6 E4EDF38E B27B944E 34884E85
GnuPG FP : 7D0B3CEB E9B85B1F 825BCECF EE05E6F6 A48F6136

[-- Attachment #2: Digital signature --]
[-- Type: application/pgp-signature, Size: 1113 bytes --]

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2018-06-28 22:24 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
     [not found] <CAAr7Pr9ijQMFE5U28p4M0H6Y+LKN5WRpzM_LAGq90juwuNsArw@mail.gmail.com>
2018-06-28 22:24 ` [gentoo-dev-announce] Re: Gentoo Github Organization hacked Robin H. Johnson

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox