5 ms·
The best part to all of this: If you generate a “CI Token” On npm. Anyone can still publish packages as you if they get ahold of it. No 2FA needed
by zackify 4y ago
The best part to all of this:
If you generate a “CI Token”
On npm. Anyone can still publish packages as you if they get ahold of it.
No 2FA needed
- raggi 4y agoThis. And this is the problem with signing too, in general. Signing is all well and good, but it doesn't do anything to demonstrate that the signed contents were prepared by a particular person. It only means they probably came from one of a set of computers. If they had adjusted to uploads require a hardware backed challenge pass, I'd be much more enthusiastic. Releases don't happen that often, adding a step to demonstrate presence to it would not be a huge burden.
- captn3m0 4y agoGitHub needs to implement OIDC auth for publishing workflows to NPM asap.