2022-05-30 Phishing PRs - Besu - LF Decentralized Trust Atlassian uses cookies to improve your browsing experience, perform analytics and research, and conduct advertising. Accept all cookies to indicate that you agree to our use of cookies on your device. Atlassian cookies and tracking notice, (opens new window) PreferencesOnly necessaryAccept all LF Decentralized Trust LF Decentralized Trust Spaces Apps Templates Create Besu All content Shortcuts Meetings Meetings  This trigger is hidden How-to articles How-to articles  This trigger is hidden Content Results will update as you type. Code of Conduct Contributing Developing and Conventions Documentation Community Governance Programs & Grants Meetings Design Documents Security Audits Start Here Performance & Stability How-to articles Incident Reports 2024-01-06 Mainnet Halting Event 2022-05-30 Phishing PRs 2021-08-04 Value transfer public transactions being rejected by Besu 2021-04-23 ATs failures 2022-11-11 Fork on Sepolia Besu Roadmap & Planning How to Contribute You‘re viewing this with anonymous access, so some content might be blocked. Close Besu / 2022-05-30 Phishing PRs More actions 2022-05-30 Phishing PRs Sally MacFarlane Owned by Sally MacFarlane Last updated: Jun 12, 2024 May 30 2022: several suspicious (closed) PRs were noticed (on besu and other non-hyperledger repos). Several attempts to add a command to our Circle CI jobs that would retrieve contents of environment variables and send to a remote server. User was reported to github (and has been removed) Issue reported to Circle CI and they reported back: secrets were not exposed Recommend disabling this CI setting: Pass secrets to builds from forked pull requests Recommend rotating credentials Unfortunately, disabling the "pass secrets to forked PRs" means that Sonar can't run on PRs plan is to temporarily disable this while we figure out a solution , multiple selections available, Related content More info Collapse 2022-01-28 Meeting Minutes 2022-01-28 Meeting Minutes Task Forces More like this 2021-12-13 Meeting Minutes 2021-12-13 Meeting Minutes Task Forces More like this Security Security Besu More like this 2023-08-08 Cacti Maintainers Agenda 2023-08-08 Cacti Maintainers Agenda Hyperledger Cacti More like this 2022 Q3 Hyperledger Cactus 2022 Q3 Hyperledger Cactus Technical Oversight Committee More like this 2021 Q1 Hyperledger Besu 2021 Q1 Hyperledger Besu Technical Oversight Committee More like this {"serverDuration": 12, "requestCorrelationId": "c9c18534abf84be5b0245c6fb3c82979"}