Javascript is not enabled. This site can still works but it'll be more interactive when javascript is enabled.
loading...
Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
insanitybit
8 hours ago
|
on: Keyv and friends compromised in active Shai-Hulud supply chain attack
Yes, you should separate "tests execute" into their own unprivileged workflows that don't have "deploy" secrets.
reply
rcxdude
8 hours ago
|
parent
You can also do the same for the build workflow, no?
reply
loading story #49171234