“A potential supply chain attack on GitHub CodeQL started simply: a publicly exposed secret, valid for 1.022 seconds at a time.”

CodeQL’s own CI leaked a GitHub token with write access inside a public debug artifact. The token lived about a second. A script still won the race and pushed a branch and tag to an action that hundreds of thousands of repos use. The security tool was one race away from being a backdoor.