|
|
|
|
|
by skipants
8 hours ago
|
|
One thing I don't quite get is how trusted publishing is supposed to be more secure. It still allows publishing if they pwn your workflow. Is it purely more secure because they can't exfiltrate your secret keys to publish again? I feel like if your workflow gets pwned you'd be rotating your keys anyways, so I'm not sure if the vendor lock-in is worth it. |
|