Hacker News new | ask | show | jobs
by nothrabannosir 3330 days ago
Right, but now you're in the "review of a PR didn't catch malicious code" boat. At which point, you've got bigger problems than leaking env vars in your CI.

Not to dismiss it---it's just a different point.