註冊並分享邀請連結,可獲得影片播放與邀請獎勵。

sudo rm -rf --no-preserve-root /
@pcaversaccio
𝐖𝐨𝐫𝐤𝐢𝐧𝐠 𝐨𝐧 𝐰𝐡𝐚𝐭'𝐬 𝐧𝐞𝐱𝐭. ꟼGꟼ: 063E 966C 93AB 4356 492F E032 7C3B 4B4B 7725 111F
加入 February 2010
333 正在關注    33.5K 粉絲
so i've been moving all of my actively maintained repos to require github actions pinned to _full-length commit shas_. on top of that, all jobs now use fine-grained perms, downloaded binaries are verified against hardcoded sha256 hashes, deps are pinned, and force-pushes to the `main`/`master` branch are disabled. there's really no good reason to risk dangling commits on your main branch. otherwise, anyone who gets compromised with write access could force-push an amended (and malicious) version of an old-looking commit. look, none of this will completely protect you from supply chain attacks, but it's one of many guardrails you can put in place. in the end, it's the combination of these measures that makes the difference hopefully. here my snekmate pr if you wanna check what i did:
顯示更多