Y
Hacker News
new
|
ask
|
show
|
jobs
by
flyingshelf
3 days ago
Keys can be reused from anywhere. Trusted publishing means the attacker must trigger the specific workflow
on GitHub
, which is more difficult and leaves trace of actions on GitHub itself.