Skip to content

fix: point stream-labs references at the streamlabs org - #60

Merged
summeroff merged 2 commits into
streamlabsfrom
fix/stream-labs-namespace
Sep 1, 2026
Merged

summeroff merged 2 commits into
streamlabsfrom
fix/stream-labs-namespace

Conversation

@nbarrett-logitech

@nbarrett-logitech nbarrett-logitech commented Sep 1, 2026 •

Copy link
Copy Markdown
Contributor

What

Points every stream-labs GitHub reference in this repo at the streamlabs org.

Why

Streamlabs renamed its GitHub organization from stream-labs to streamlabs. GitHub keeps 301 redirects from the old namespace, but only until somebody claims that namespace and creates a repository with a matching name. At that point the redirect stops resolving and the URL points at their repository instead.

The stream-labs namespace is no longer under our control. It is currently held by an organization created on 2026-08-23 that has no public repositories, which is the only reason the redirects still resolve today. They break as soon as a matching repository name is created there.

Tracked as HackerOne #3065731 (Critical).

Impact

This workflow checks out stream-labs/symsrv-scripts and then executes ./symsrv-scripts/main.bat, in a job that has the symbol-server AWS credentials in its environment. That checkout resolves only through the rename redirect. If the redirect breaks, the job runs code from a repository we do not control, with those credentials in scope.

The -repo_userId value is a separate issue in the same file: it is passed through to github-sourceindexer.ps1 and written into the generated PDBs as the source-fetch URL, so published debug symbols currently direct debuggers at the old namespace.

Also in this PR — two more build-time fetches through the old namespace

Found while sweeping the rest of the repo, and they belong to the same class as the workflow issue rather than to cosmetic metadata:

1. CMake fetches and runs a script from the old namespace.

FetchContent_Declare(deps_checker URL
  "https://raw.githubusercontent.com/stream-labs/obs-studio-node/staging/dependency_checker/check_dependencies.cmd")

raw.githubusercontent.com resolves the old org name directly — verified, it returns HTTP 200 with no redirect hop. So if a repository named obs-studio-node appears under the stream-labs namespace, this fetch starts serving that file, and the build executes it.

2. Repository metadata — package.json repository/bugs/homepage URLs and, where present, CHANGELOG links. Cosmetic, but they are what people copy clone commands out of.

The stream-labs GitHub namespace is no longer under our control. These
references resolve only through GitHub's org-rename redirect, which breaks
as soon as a repository with a matching name is created under that
namespace.

Refs HackerOne #3065731
Covers the build-time fetches as well as repository metadata:

- CMake FetchContent pulls check_dependencies.cmd from
  raw.githubusercontent.com under the old namespace and runs it during the
  build. raw.githubusercontent.com resolves the old org name directly, so
  this would serve a third party's file if that namespace gained a
  matching repository.
- obs-studio-node additionally clones StackWalker from the old namespace
  via FetchContent GIT_REPOSITORY.

Refs HackerOne #3065731
@summeroff
summeroff merged commit 6148811 into streamlabs Sep 1, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants