Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This has nothing to do with trusting packages; it’s about delegating publishing authority to a service like GitHub Actions.


How do you know that what the action is doing is trustworthy?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: