GitHub ืขื“ื›ื ื” ืžืคืชื—ื•ืช GPG ืขืงื‘ ืคื’ื™ืขื•ืช ื“ืœื™ืคื” ืฉืœ ืžืฉืชื ื” ืกื‘ื™ื‘ื”

GitHub ื—ืฉืคื” ืคื’ื™ืขื•ืช ื”ืžืืคืฉืจืช ื’ื™ืฉื” ืœืชื•ื›ืŸ ืฉืœ ืžืฉืชื ื™ ืกื‘ื™ื‘ื” ืฉื ื—ืฉืคื• ื‘ืžื›ื•ืœื•ืช ื”ืžืฉืžืฉื•ืช ื‘ืชืฉืชื™ืช ื™ื™ืฆื•ืจ. ื”ืคื’ื™ืขื•ืช ื”ืชื’ืœืชื” ืขืœ ื™ื“ื™ ืžืฉืชืชืฃ Bug Bounty ืฉื—ื™ืคืฉ ืคืจืก ืขืœ ืžืฆื™ืืช ื‘ืขื™ื•ืช ืื‘ื˜ื—ื”. ื”ื‘ืขื™ื” ืžืฉืคื™ืขื” ื’ื ืขืœ ืฉื™ืจื•ืช GitHub.com ื•ื’ื ืขืœ ืชืฆื•ืจื•ืช GitHub Enterprise Server (GHES) ื”ืคื•ืขืœื•ืช ื‘ืžืขืจื›ื•ืช ืžืฉืชืžืฉ.

ื ื™ืชื•ื— ื”ื™ื•ืžื ื™ื ื•ื‘ื™ืงื•ืจืช ื”ืชืฉืชื™ืช ืœื ื”ืขืœื• ืขืงื‘ื•ืช ืฉืœ ื ื™ืฆื•ืœ ืฉืœ ื”ืคื’ื™ืขื•ืช ื‘ืขื‘ืจ ืœืžืขื˜ ืคืขื™ืœื•ืชื• ืฉืœ ื”ื—ื•ืงืจ ืฉื“ื™ื•ื•ื— ืขืœ ื”ื‘ืขื™ื”. ืขื ื–ืืช, ื”ืชืฉืชื™ืช ื”ื—ืœื” ืœื”ื—ืœื™ืฃ ืืช ื›ืœ ืžืคืชื—ื•ืช ื”ื”ืฆืคื ื” ื•ื”ืื™ืฉื•ืจื™ื ืฉืขืœื•ืœื™ื ืœื”ื™ืคื’ืข ืื ื”ืคื’ื™ืขื•ืช ืžื ื•ืฆืœืช ืขืœ ื™ื“ื™ ืชื•ืงืฃ. ื”ื—ืœืคืช ืžืคืชื—ื•ืช ืคื ื™ืžื™ื™ื ื”ื•ื‘ื™ืœื” ืœื”ืคืจืขื” ื‘ืฉื™ืจื•ืชื™ื ืžืกื•ื™ืžื™ื ื‘ื™ืŸ ื”-27 ืœ-29 ื‘ื“ืฆืžื‘ืจ. ืžื ื”ืœื™ GitHub ื ื™ืกื• ืœืงื—ืช ื‘ื—ืฉื‘ื•ืŸ ืืช ื”ื˜ืขื•ื™ื•ืช ืฉื ืขืฉื• ื‘ืžื”ืœืš ืขื“ื›ื•ืŸ ื”ืžืคืชื—ื•ืช ืฉื”ืฉืคื™ืขื• ืขืœ ืœืงื•ื—ื•ืช ืฉื ืขืฉื• ืืชืžื•ืœ.

ื‘ื™ืŸ ื”ื™ืชืจ, ืขื•ื“ื›ืŸ ืžืคืชื— ื”-GPG ื”ืžืฉืžืฉ ืœื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช ืขืœ ื”ืชื—ื™ื™ื‘ื•ื™ื•ืช ืฉื ื•ืฆืจื• ื‘ืืžืฆืขื•ืช ืขื•ืจืš ื”ืื™ื ื˜ืจื ื˜ ืฉืœ GitHub ื‘ืขืช ืงื‘ืœืช ื‘ืงืฉื•ืช ืžืฉื™ื›ื” ื‘ืืชืจ ืื• ื‘ืืžืฆืขื•ืช ืขืจื›ืช ื”ื›ืœื™ื Codespace. ื”ืžืคืชื— ื”ื™ืฉืŸ ื—ื“ืœ ืœื”ื™ื•ืช ืชืงืฃ ื‘-16 ื‘ื™ื ื•ืืจ ื‘ืฉืขื” 23:23 ืฉืขื•ืŸ ืžื•ืกืงื‘ื”, ื•ื‘ืžืงื•ืžื• ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ืžืคืชื— ื—ื“ืฉ ืžืืชืžื•ืœ. ื”ื—ืœ ืžื”-XNUMX ื‘ื™ื ื•ืืจ, ื›ืœ ื”ื”ืชื—ื™ื™ื‘ื•ื™ื•ืช ื”ื—ื“ืฉื•ืช ืฉื ื—ืชืžื• ืขื ื”ืžืคืชื— ื”ืงื•ื“ื ืœื ื™ืกื•ืžื ื• ื›ืžืื•ืžืชื•ืช ื‘-GitHub.

16 ื‘ื™ื ื•ืืจ ื’ื ืขื“ื›ื ื• ืืช ื”ืžืคืชื—ื•ืช ื”ืฆื™ื‘ื•ืจื™ื™ื ื”ืžืฉืžืฉื™ื ืœื”ืฆืคื ืช ื ืชื•ื ื™ ืžืฉืชืžืฉ ืฉื ืฉืœื—ื• ื“ืจืš ื”-API ืœ-GitHub Actions, GitHub Codespaces ื•-Dependabot. ืœืžืฉืชืžืฉื™ื ื”ืžืฉืชืžืฉื™ื ื‘ืžืคืชื—ื•ืช ืฆื™ื‘ื•ืจื™ื™ื ื‘ื‘ืขืœื•ืช GitHub ื›ื“ื™ ืœื‘ื“ื•ืง ื”ืชื—ื™ื™ื‘ื•ื™ื•ืช ืžืงื•ืžื™ื•ืช ื•ืœื”ืฆืคื™ืŸ ื ืชื•ื ื™ื ื‘ืžืขื‘ืจ, ืžื•ืžืœืฅ ืœื•ื•ื“ื ืฉื”ื ืขื“ื›ื ื• ืืช ืžืคืชื—ื•ืช GitHub GPG ืฉืœื”ื ื›ืš ืฉื”ืžืขืจื›ื•ืช ืฉืœื”ื ื™ืžืฉื™ื›ื• ืœืคืขื•ืœ ืœืื—ืจ ืฉื™ื ื•ื™ ื”ืžืคืชื—ื•ืช.

GitHub ื›ื‘ืจ ืชื™ืงืŸ ืืช ื”ืคื’ื™ืขื•ืช ื‘-GitHub.com ื•ืฉื—ืจืจ ืขื“ื›ื•ืŸ ืžื•ืฆืจ ืขื‘ื•ืจ GHES 3.8.13, 3.9.8, 3.10.5 ื•-3.11.3, ื”ื›ื•ืœืœ ืชื™ืงื•ืŸ ืขื‘ื•ืจ CVE-2024-0200 (ืฉื™ืžื•ืฉ ืœื ื‘ื˜ื•ื— ื‘ื”ืฉืชืงืคื•ื™ื•ืช ื”ืžื•ื‘ื™ืœ ืœ ื‘ื™ืฆื•ืข ืงื•ื“ ืื• ืฉื™ื˜ื•ืช ื”ื ืฉืœื˜ื•ืช ืขืœ ื™ื“ื™ ื”ืžืฉืชืžืฉ ื‘ืฆื“ ื”ืฉืจืช). ื”ืชืงืคื” ืขืœ ื”ืชืงื ื•ืช GHES ืžืงื•ืžื™ื•ืช ื™ื›ื•ืœื” ืœื”ืชื‘ืฆืข ืื ืœืชื•ืงืฃ ื”ื™ื” ื—ืฉื‘ื•ืŸ ืขื ื–ื›ื•ื™ื•ืช ื‘ืขืœื™ ื”ืืจื’ื•ืŸ.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”