Fake GitHub commits can trick developers into using malicious code
Threat actors can easily alter the identity and timestamp associated with software updates, putting developers at serious risk, Checkmarx research shows. http://news.poseidon-us.com/SV5vLz