Register and share your invite link to earn from video plays and referrals.

sudo rm -rf --no-preserve-root /
@pcaversaccio
𝐖𝐨𝐫𝐤𝐢𝐧𝐠 𝐨𝐧 𝐰𝐡𝐚𝐭'𝐬 𝐧𝐞𝐱𝐭. ꟼGꟼ: 063E 966C 93AB 4356 492F E032 7C3B 4B4B 7725 111F
Joined February 2010
333 Following    33.5K Followers
so i've been moving all of my actively maintained repos to require github actions pinned to _full-length commit shas_. on top of that, all jobs now use fine-grained perms, downloaded binaries are verified against hardcoded sha256 hashes, deps are pinned, and force-pushes to the `main`/`master` branch are disabled. there's really no good reason to risk dangling commits on your main branch. otherwise, anyone who gets compromised with write access could force-push an amended (and malicious) version of an old-looking commit. look, none of this will completely protect you from supply chain attacks, but it's one of many guardrails you can put in place. in the end, it's the combination of these measures that makes the difference hopefully. here my snekmate pr if you wanna check what i did:
Show more