zlacker

[parent] [thread] 1 comments
1. hn_thr+(OP)[view] [source] 2020-04-15 02:39:59
I agree, but GitHub must fix the security nightmare that is waiting to happen with GitHub actions marketplace. Seems like this would be such an easy fix, too.
replies(1): >>pknopf+E6
2. pknopf+E6[view] [source] 2020-04-15 03:51:24
>>hn_thr+(OP)
Organizations can enforce that their repos use only actions that are within the repo, making the build more secure, controlled and auditable.
[go to top]