raycast / raycast/github-actions

Unauthorised access and negative impacts

Open
#11 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Shell
Stars
40
Forks
12
PR merge metrics
No merged PRs in 30d

Description

I’m not sure if I’m contacting the security team.
I discovered unauthorised activities in my GitHub and link google cloud account.
This is my second account to continue unauthorised activities involving CI/CD when it is obviously beyond my expertise. Any code pushed is negatively impacting my iOS, iPad os, macOS, windows and Linux. CVE-2023, ( before the last CVE. This was the vulnerability exploited. I don’t feel confident divulging more critical information, as the spying activities continues to wreak havoc on my personal and wor accounts (NHS GP)
I await your reply to discuss the next stepst.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

The report identifies GitHub Actions/CI/CD and a linked Google Cloud account, but names no file, test, or reproducible failure. Start with security-team or maintainer triage of the reported account activity; done requires an agreed scope and directed remediation.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions, google-cloud
Domain
ci-cd, cloud, security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
10/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.