Disrupting supply chain attacks on NPM and GitHub Actions

(github.blog)

32 points | by nyku 2 hours ago

1 comments

  • DiabloD3 1 hour ago
    [flagged]
    • theF00l 53 minutes ago
      The job can require you to
      • DiabloD3 44 minutes ago
        [flagged]
        • UqWBcuFx6NV4r 18 minutes ago
          These comments should be removed r from HN, because they in no way actually add to the conversation. They aren’t intelligent, they aren’t insightful, they aren’t actionable, and they don’t invite a genuine reply. All you’re saying is that you happen to not use these technologies yourself – something that I’m sure is only by happenstance – and that you feel superior for it.

          This is a blog post by GitHub. what are you suggesting that these employees do? Simply ignore that they exist? Regardless of whether or not you use them, they still exist.

          • anon48293 8 minutes ago
            > This is a blog post by GitHub. what are you suggesting that these employees do? Simply ignore that they exist?

            The buggy, insecure feature that is GitHub actions? Yes, preferably so.

        • x86a 38 minutes ago
          This is such a myopic take
        • baby_souffle 32 minutes ago
          GitHub actions doesn’t really make you a js shop
    • rho138 1 hour ago
      > Opting out of toxic ecosystems is a valid option

      Quick, everyone break out the pitchforks for a valid analysis of a game! /s