Skip to content

Conversation

@barakharyati
Copy link
Contributor

@barakharyati barakharyati commented Dec 9, 2025

Information sent in email @marc0der @helpermethod

@barakharyati
Copy link
Contributor Author

Hi SdKman team
@marc0der @helpermethod @eddumelendez @SvMak @hamzaremmal
This is an emergency risk for repo takeover Please review ASAP

@barakharyati
Copy link
Contributor Author

I also strongly recommend creating a security advisory for private disclosure.

@marc0der marc0der closed this Dec 10, 2025
@barakharyati
Copy link
Contributor Author

barakharyati commented Dec 12, 2025

Hi @marc0der, I emailed you about that issue.

@barakharyati barakharyati changed the title [Security] Critical vulnerability fix: Prevent Repository Takeover Hardening Dec 12, 2025
@marc0der marc0der reopened this Dec 12, 2025
@marc0der marc0der merged commit d41158d into sdkman:master Dec 12, 2025
3 checks passed
@barakharyati
Copy link
Contributor Author

vulnerability info shared in GHSA

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants