Hacker News new | ask | show | jobs
by maroon_unperson 263 days ago
It would be great to have an automated workflow for granting one-time authorisation for CI to publish a package.

I'd like the easy of having CI sign and release on merge but with the security of local 2FA or hardware signing tokens so malicious access can be guarenteed not to be able to distribute a release.