Y
Hacker News
new
|
ask
|
show
|
jobs
by
greatjack613
1152 days ago
The "blue badges" of software packages. Honestly not a bad idea but who and what determines a package to be "trusted"? Will there be transparency into the decisions?
2 comments
woodruffw
1152 days ago
This has nothing to do with trusting packages; it’s about delegating publishing authority to a service like GitHub Actions.
link
verdverm
1151 days ago
How do you know that what the action is doing is trustworthy?
link
Takennickname
1151 days ago
You didn't read the link.
link