@
cecil2016 你但凡看下自己发的这个 SU 修的是什么 CVE 呢?
In the course of our investigation of AWS-2025-016, we determined that Amazon Q Developer for VS Code Extension had an inappropriately scoped GitHub token in their CodeBuild configuration.
With that access token, the threat actor was able to commit malicious code into the extension's open-source repository that was automatically included in a release.
After we identified this, we immediately revoked and replaced the credentials, removed the malicious code from the code base, and subsequently released Amazon Q Developer for VS Code Extension version 1.85.0.
这个修的 Github Token Scope 设的太大的问题,跟你发的代码有一毛钱关系?