|
|
|
|
|
by chippiewill
588 days ago
|
|
It's not about the package maintainer, it's about the trustworthiness of the OIDC issuer to prove the identity of a user. A poorly maintained issuer could leak their secret keys, allowing anyone to impersonate any package from their service. |
|
I mean it only proves I authenticated successfully. Nothing else.