Open Issues Need Help
View All on GitHubAI Summary: Analyze a GitHub project demonstrating a vulnerability that allows automated farming of contribution points using GitHub Actions. The task involves understanding the provided workflow file, assessing its impact, and potentially suggesting mitigations. This includes reviewing the project's README, a related GitHub issue report, and evaluating the potential security implications.
Auto Farms Points BUG in Github Author: Bocaletto Luca Hi there! I’m Luca (@bocaletto-luca), and I’ve put together this repo to demonstrate a surprising “feature” (or vulnerability?) in GitHub’s contribution model. With a single workflow file, you can automatically farm commits, issues, PRs, wiki edits, releases and comments every hour—artificially