HNHacker News
TopNewBestAskShowJobs

gose1

25 karma · joined January 5, 2012

submissionscomments
gose1··on How to harden GitHub Actions
> Safely Writing GitHub Workflows

If you are looking for ways to identify common (and uncommon) vulnerabilities in Action workflows, last month GitHub shipped support for workflow security analysis in CodeQL and GitHub Code Scanning (free for public repos): https://github.blog/changelog/2025-04-22-github-actions-work....

The GitHub Security Lab also shared a technical deep dive and details of vulnerabilities that they found while helping develop and test this new static analysis capability: https://github.blog/security/application-security/how-to-sec...

gose1··on GitHub's Content Security Policy journey
Policies set via meta tags can only be made subsequently more restrictive: https://w3c.github.io/webappsec-csp/#multiple-policies.
gose1··on CryptDown – Client-side AES-encrypted Markdown pastes
https://cryptdown.eu/view/23mz2dmpdq5co - password: lolz

and this is why we don't like crypto in the browser...

gose1··on Texting-Enabled Raspberry-Pi-Powered Espresso Machine
Nice, here is the current progress of my Silvia / PID monitoring: http://i.imgur.com/mis4L.png.

I'm using Arduino + TC4 shield for PID and interfacing w/ thermocouples, SSR, and opto-isolators (for front panel switch sensing). Serial to RasPi to web sockets for the frontend.

gose1··on Ginzametrics Open Sources Odin, A Cookie-Based Single Sign On for Apache
Also, using sha1_hex(secret+...) and calling it HMAC is a slippery slope (see http://netifera.com/research/flickr_api_signature_forgery.pd...). Although it's seemingly not exploitable due to the structure of the data, look into using a proper HMAC (RFC 2104) to prevent length-extension attacks.