|
|
|
|
|
by benoau
183 days ago
|
|
You can set up your repo to disable pushing directly to branches like main and require MFA to use the org admin account, so something malicious would need to push to a benign branch and separately be merged into one that deploys come from. |
|