Hacker News new | ask | show | jobs
by lrvick 1265 days ago
Testing is a separate concern than supply chain security. Testing should also never require any secrets useful to an adversary, so third party hosted CI is low risk here.