Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
cyphar
5 months ago
|
parent
|
context
|
favorite
| on:
GitHub Actions has a package manager, and it might...
TFA mentions this option and then goes on at some length to explain that this doesn't help for transitive dependencies, which is how these attacks usually work.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: