writeups.xyz writeups.xyz / Dependabot Confusion: Gaining Access to Private GitHub Repositories using Dependabot

Submitter : c2a

Date: 6 May 2023

Bounty : 2,500

Vulnerabilities :

Programs :

Authors :

Link :
https://giraffesecurity.dev/posts/dependabot-confusion/