Remix.run Logo
rawgabbit an hour ago

Help me understand. Snowflake configured their Github repo to allow auto fixes by Copilot. It got merged automatically without anyone's review? And introduced essentially script-injection vulnerability through the title field?

If this is the case, I would say Snowflake should shut down its repo and get off Github asap.

rafram an hour ago | parent [-]

No. A Snowflake maintainer opened a PR, Copilot suggested a change (introducing a vulnerability), the maintainer accepted and committed it to their PR, and another Snowflake maintainer approved and merged the PR.

lelanthran 26 minutes ago | parent [-]

And that's going to continue because no one is reading the code even when they approve it.

It's a very strange thing indeed, but not unexpected: we warned that skills not used will eventually atrophy.