The jupyterlab/maintainer-tools update-snapshots-checkout action uses one-second timestamps to reject pull request updates after an authorized comment. An attacker can win a same-second race, causing a privileged workflow to check out and execute attacker-controlled code.
The jupyterlab/maintainer-tools update-snapshots-checkout action uses one-second timestamps to reject pull request updates after an authorized comment. An attacker can win a same-second race, causing a privileged workflow to check out and execute attacker-controlled code.