logoalt Hacker News

mmariantoday at 7:15 PM1 replyview on HN

Agreed. Good news is GitHub will address that with Immutable Releases https://github.blog/news-insights/product-news/whats-coming-... You won't even need to use commit SHA as long as the maintainer follows this approach.


Replies

phist_mcgeetoday at 8:14 PM

What an absolute joke that it has taken GitHub this long to clean up it's act when it comes to supply chain security.