logoalt Hacker News

thaynelast Thursday at 2:04 AM1 replyview on HN

It also make it impossible to publish using CI, which is problematic for projects with frequent releases. And trusted publishing doesn't solve that if you use self-hosted CI.


Replies

fc417fc802last Thursday at 6:13 AM

> trusted publishing doesn't solve that if you use self-hosted CI

Is there any particular reason for the whitelist approach? Standing on the sidelines it appears wholly unnecessary to me. Authentication that an artifact came from a given CI system seems orthogonal to the question of how much trust you place in a given CI system.

show 1 reply