I'm pretty sure it didn't impact anybody.
I'm pretty sure it didn't impact anybody.
Not very nice to be a victim of that but at least there is no doubt whether you're vulnerable or not.
The timeline also suggests that the malicious content was made after the break-in and not planned beforehand?
Does anybody know why this is the case?
[0] https://github.com/dantrell/gentoo-project-gnome-without-sys...
Doesn't sound to me as if it's not a mirror.
Though I guess you could say as their CI depended on this mirror, it had a higher status than normal mirrors.
From their incident report (under https://wiki.gentoo.org/wiki/Github/2018-06-28#What_went_bad... ): "The systemd repo is not mirrored from Gentoo, but is stored directly on GitHub."
And from their Action Items: "mirror systemd repo on git.gentoo.org"
I'm curious why they seem to treat this repo differently from the others, using GitHub as authoritative and adding a mirror to git.gentoo.org rather than making git.gentoo.org authoritative and mirroring to GitHub.