Does anyone know the purpose of the following repository? (not ansible/ansible)
My colleague misunderstood it as an ansible-core repository.
The official ansible-core repository is ansible/ansible, right?
Does anyone know the purpose of the following repository? (not ansible/ansible)
My colleague misunderstood it as an ansible-core repository.
The official ansible-core repository is ansible/ansible, right?
No idea, I havenāt seen this before. It seems to be an up-to-date mirror of ansible/ansible (but I havneāt checked in detail, it only looks that way on a first glance), but I have no idea by whom⦠@gundalow @Core are you aware of this? Is this an official repository by Red Hat, or some third-party fork/mirror?
Hi,
Iāve never heard of https://github.com/ansible-core before. It is not official. I donāt believe itās created by anybody related to Red Hat.
Iām guessing that someone created a GitHub user called āansible-coreā and forked ansible/ansible.
From a very quick look, I donāt see local commits, so I canāt find contact info
Thank you for the information.
Iāll keep in mind that itās not an official repository.
Iāve asked internally (Red Hat) for some advice on this.
I doubt itās ours. The org doesnāt have public members. But the branches page (Branches Ā· ansible-core/ansible Ā· GitHub) leaked that devel was last updated by a noname account tekicat (tekicat) Ā· GitHub 13 hours ago. They seemed to have pushed the same commit as in the official repo. But obviously, I wouldnāt trust the impersonator. This could be either somebody inexperienced or a malicious actor preparing for a supply chain exploit long-term.
The tags and non-default branches havenāt been synched from the official repository for like two years but somebody keeps devel in sync. This likely means that it was forked 2 years ago.
I think we should report the org to GH for impersonation.
UPD: reported the org
Thank you for the details!
This is what GH responded to my impersonation report:
Hello,
Thanks for reaching out.
We understand that copyrighted, trademarked, or private content may get published on GitHub ā either accidentally or on purpose ā sometimes in repositories that you do not own. Because the nature of this content varies, and because of different applicable laws, each category has its own, distinct reporting requirements outlined in our policies.
If youād like to request that content be removed from GitHub, please take some time to acquaint yourself with each of these policies and their respective reporting requirements before submitting a report.
You can find more information about our policies here:
Submitting content removal requests
Additionally, you may also want to review this blog post on how to handle sensitive data leaks:
Full exposure: A practical approach to handling sensitive data leaks
Please let us know if you have any other questions.
Regards,
GitHub Trust & Safety
cc @gundalow
@webknjaz As I havenāt been though that process before, thank you for the details.
Iām waiting to hear back from Red Hat Legal, and will update the thread once Iāve got an update.
This has been reported to GitHub, Iāll report back here once I have an update.