fix: point stream-labs references at the streamlabs org - #60
Merged
Merged
Conversation
The stream-labs GitHub namespace is no longer under our control. These references resolve only through GitHub's org-rename redirect, which breaks as soon as a repository with a matching name is created under that namespace. Refs HackerOne #3065731
Covers the build-time fetches as well as repository metadata: - CMake FetchContent pulls check_dependencies.cmd from raw.githubusercontent.com under the old namespace and runs it during the build. raw.githubusercontent.com resolves the old org name directly, so this would serve a third party's file if that namespace gained a matching repository. - obs-studio-node additionally clones StackWalker from the old namespace via FetchContent GIT_REPOSITORY. Refs HackerOne #3065731
igorsgm
approved these changes
Sep 1, 2026
summeroff
approved these changes
Sep 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Points every
stream-labsGitHub reference in this repo at thestreamlabsorg.Why
Streamlabs renamed its GitHub organization from
stream-labstostreamlabs. GitHub keeps 301 redirects from the old namespace, but only until somebody claims that namespace and creates a repository with a matching name. At that point the redirect stops resolving and the URL points at their repository instead.The
stream-labsnamespace is no longer under our control. It is currently held by an organization created on 2026-08-23 that has no public repositories, which is the only reason the redirects still resolve today. They break as soon as a matching repository name is created there.Tracked as HackerOne #3065731 (Critical).
Impact
This workflow checks out
stream-labs/symsrv-scriptsand then executes./symsrv-scripts/main.bat, in a job that has the symbol-server AWS credentials in its environment. That checkout resolves only through the rename redirect. If the redirect breaks, the job runs code from a repository we do not control, with those credentials in scope.The
-repo_userIdvalue is a separate issue in the same file: it is passed through togithub-sourceindexer.ps1and written into the generated PDBs as the source-fetch URL, so published debug symbols currently direct debuggers at the old namespace.Also in this PR — two more build-time fetches through the old namespace
Found while sweeping the rest of the repo, and they belong to the same class as the workflow issue rather than to cosmetic metadata:
1. CMake fetches and runs a script from the old namespace.
raw.githubusercontent.comresolves the old org name directly — verified, it returnsHTTP 200with no redirect hop. So if a repository namedobs-studio-nodeappears under thestream-labsnamespace, this fetch starts serving that file, and the build executes it.2. Repository metadata —
package.jsonrepository/bugs/homepageURLs and, where present,CHANGELOGlinks. Cosmetic, but they are what people copy clone commands out of.