Monday, March 29, 2021 [Tweets] [Favorites]

PHP’s Git Server Compromised

Nikita Popov (via Hacker News):

Yesterday (2021-03-28) two malicious commits were pushed to the php-src repo from the names of Rasmus Lerdorf and myself. We don’t yet know how exactly this happened, but everything points towards a compromise of the git.php.net server (rather than a compromise of an individual git account).

While investigation is still underway, we have decided that maintaining our own git infrastructure is an unnecessary security risk, and that we will discontinue the git.php.net server. Instead, the repositories on GitHub, which were previously only mirrors, will become canonical.

Previously:

Update (2021-04-07): Nikita Popov (via Hacker News):

We no longer believe the git.php.net server has been compromised. However, it is possible that the master.php.net user database leaked.

Comments

Stay up-to-date by subscribing to the Comments RSS Feed for this post.

Leave a Comment