Hacker News new | ask | show | jobs
by KaiserPro 2383 days ago
It depends on your threat model.

If you are a large company tech company (1-5k employees) there are far bigger risks than dodgy binary builds from upstream. (like leaked API keys to github...)

However, if you are a hyperscale, high value company (ie a place which has enough data or digital cash to be worth dicking with) then its a worthy problem.