Hacker News new | ask | show | jobs
by jermo 1954 days ago
A lot of projects publish to Central from cloud CIs. That means that private keys are stored in config/secrets. It is debatable whether that makes the artifacts more reliable since you have to trust the CI.