I don't think there are any endpoints on http://
GitHub.com itself that could expose logs of incoming GET requests to anyone outside of GitHub/microsoft employees It does make me nervous that all of that domain is allow-listed though, feels like the riskiest entry in there
GitHub Domain Allow-listing Security Risk Analysis
By
–
Leave a Reply