Why Nostr? What is Njump?
2024-06-03 13:14:27

Jeff Triplett on Nostr: While this is good advice, pinned GitHub Actions are not immutable because they share ...

While this is good advice, pinned GitHub Actions are not immutable because they share the same syntax as a label.

This means that someone can delete the image tied to an SHA and replace it with a label (that matches the SHA) to point it to a different image.

GitHub could fix this by migrating to a new syntax, but I suspect Docker is the underline issue here. https://s.ovalerio.net/@dethos/112552632476543887
Author Public Key
npub1nsp3hg75ge84dn5fttlkpxpxnj0dfl697239dtyz4js3mdw2jllqf8ahke