Hacker News new | past | comments | ask | show | jobs | submit | niros_valtos's comments login

Download the GitHub CLI. Run ‘ gh pr create’. Good luck!


This is great! Github Copilot used to summarize our PRs - I think it can work perfectly as a Github workflow to add comments to newly opened PRs. Can be a nice experiment to use multiple models and compare the comments to determine what works better.


The risk severity determination is interesting! If the token of the current user has a site admin permission, the risk is higher.



I like the way then handle the communication about the incident. There 2 ways to interpret the message: 1. Someone managed to get access to dev credentials and exfiltrated source code (the part that is explicitly mentioned). 2. Someone managed to push code on behalf of the compromised account and they responded to this change (not mentioned, but otherwise how would they know the account was compromised - each SCM has its logging limitations).


This is great stuff! I read This adjacent research, which seems to complement yours - https://www.arnica.io/blog/how-do-top-open-source-projects-p...


Super interesting!!! As a former penetration tester, I had several opportunities to move to the other side of the law. The money offered to me was extremely high, and I believe I could be really good at these ops. With that said, I decided to live “boring” life. This story is interesting just because it makes me wonder how my life would’ve looked like if I chose the other side.


Remember stuxnet? Supply chain security in its glory…


You can use a test mode with Stripe. You can run as many APIs as you want to generate data. Am I missing something?


Yes you're right. In the Github link in the post, that's what they do as well. It helps to a small degree, but it's not nearly enough data for building an analytics app.

I was hoping there would be a dataset that would follows real world patterns vs whatever I generate from my understanding of the api.


What real world patterns though?

Your traffic, stats, and bounce rates, returning customer rates will vary practically 100% depending on:

- If you sell a good physical product

- If you dropship utter rubbish and advertise on Instagram spam stories where people buy a single thing and never come back or chargeback instead

- Digital items for games for adults

- Digital items for games for kids


I would expect to see a code example, but overall makes sense.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: