logoalt Hacker News

progbitsyesterday at 11:16 AM3 repliesview on HN

Why do you keep using token auth? This is unacceptable negligence these days.

NPM supports GitHub workflow OIDC and you can make that required, disabling all token access.


Replies

timglyesterday at 11:17 AM

Yep, we are moving to workflow OIDC as the next step in recovery.

junonyesterday at 12:34 PM

OIDC is not a silver bullet either and has its own set of vectors to consider too. If it works for your org model then great, but it doesn't solve every common scenario.

show 1 reply
huflungdungyesterday at 12:19 PM

[dead]