jeremylong / musical-octo-carnival

A journey through the insecure defaults in GitHub Actions - wait who committed code to my repo?
Apache License 2.0
3 stars 1 forks source link

Act3: Improve Testing #3

Closed jeremylong closed 2 years ago

jeremylong commented 2 years ago

Act 3 introduces a technique to hide code by abusing the default diff UI in GitHub. There is no indiction that the same code from Act 1 has been re-introduced on lines 56 & 57.

There is no line wrap in the Unified view - or even any indication that code goes off to the right (not even a scroll bar). One must switch to the Split view to see the line wrap.