Hacker News new | ask | show | jobs
by jhutchings0 1519 days ago
Thanks for your comment! I'm Justin Hutchings, the author of that blog, and you're right that it was pretty narrowly focused on dependencies. We've been making a concerted effort to post about a number of security topics lately to provide best practices for users, everything from coordinated vulnerability disclosure, to how to protect from supply chain risks.

You can find all of our security related blogs here: https://github.blog/category/security/

And thanks for sharing that blog, I'll pass it along to my colleagues in the Actions team.