3 ms·
Having both is really where things are at. That way you can verify that the tools being used for the build aren't doing something behind your back and that the
by scheme271 1y ago
Having both is really where things are at. That way you can verify that the tools being used for the build aren't doing something behind your back and that the code that you see is what you're getting.
- WhyNotHugo 1y agoGitHub actions encourages using mutable references for “workflows”, so the inputs used during the build process can change before and after the build. That seems like an obvious vector for doing something behind your back.