zlacker

[parent] [thread] 2 comments
1. jjeaff+(OP)[view] [source] 2020-04-14 17:54:26
I use Gitlab's CI runners and I agree. However, I am pretty excited about the direction that Github is going with their actions. Having a directory of user created actions and integrations seems like gold to me and I hope Gitlab starts leaning that way soon.
replies(1): >>hn_thr+Te1
2. hn_thr+Te1[view] [source] 2020-04-15 02:39:59
>>jjeaff+(OP)
I agree, but GitHub must fix the security nightmare that is waiting to happen with GitHub actions marketplace. Seems like this would be such an easy fix, too.
replies(1): >>pknopf+xl1
◧◩
3. pknopf+xl1[view] [source] [discussion] 2020-04-15 03:51:24
>>hn_thr+Te1
Organizations can enforce that their repos use only actions that are within the repo, making the build more secure, controlled and auditable.
[go to top]