Skip to content

docs: minor documentation improvements#1325

Closed
ByteWarden59 wants to merge 1 commit intonest:masterfrom
ByteWarden59:poc-nestml-1772094808
Closed

docs: minor documentation improvements#1325
ByteWarden59 wants to merge 1 commit intonest:masterfrom
ByteWarden59:poc-nestml-1772094808

Conversation

@ByteWarden59
Copy link

PoC: Security Research - PR Bypass + Token Exfil

Marker: NESTML_POC_1772094808_jlxhbboy

This PR demonstrates that fork PR code executes in CI without maintainer approval.

  • nestml-build (pull_request): unit_tests runs pytest on PR code
  • continuous_benchmarking (pull_request_target): checkout PR head, GITHUB_TOKEN exposed

@clinssen
Copy link
Contributor

clinssen commented Feb 26, 2026

Thank you for bringing this to our attention. However, I would appreciate if you would have followed responsible disclosure guidelines (see e.g. https://cheatsheetseries.owasp.org/cheatsheets/Vulnerability_Disclosure_Cheat_Sheet.html).

Closing as fixed by #1327.

Edit: I noticed that NEST Simulator has a well-defined security policy, available at https://github.com/nest/nest-simulator/blob/master/SECURITY.md. I have created a PR to create a similar notice on the NESTML repository (#1331).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants