The Homebrew package manager for macOS and Linux has fixed an issue that could have been exploited by miscreants to run malicious code on people’s computers. Specifically, the project’s GitHub Actions setup could have been abused to sneak arbitrary Ruby code into its Cask repositories, security researcher RyotaK discovered and disclosed via HackerOne.
Read full article on The Register