Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
undefined | Better HN
0 points
imglorp
1mo ago
0 comments
Share
Yes, true, but at least the fire won't spread through this one point. Hopefully all of your upstreams can be persuaded to pin also.
0 comments
default
newest
oldest
franktankbank
1mo ago
Doesn't a single compromised action in the chain cause the whole to be fucked? Pinning the top level doesn't prevent any spread.
teaearlgraycold
1mo ago
Might want to vendor everything?
lijok
1mo ago
That’s the way to go indeed. We’ve done it, not difficult, just a bit of gruntwork to keep them updated when needed
franktankbank
1mo ago
I don't know what this means in this context.
teaearlgraycold
1mo ago
Make copies of the entire GitHub action dependency tree.
j
/
k
navigate · click thread line to collapse