Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
cedws
13 days ago
|
parent
|
context
|
favorite
| on:
GitHub Actions has a package manager, and it might...
I've also found many Actions that do other dodgy stuff, like pulling and executing unpinned scripts from external websites, or installing unpinned binaries from GitHub releases. Pinning an Action isn't enough, you have to audit it.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: