Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
electricapps
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
3 ms
·
1.
▲
by
electricapps
5mo ago
Great writeup. Though combined with the lack of lockfiles for transitive actions, relying purely on static analysis is tough. Linter like zizmor are great, but they struggle with deep composite actions trees and runtime template injection.
2.
▲
hasp: A paranoid scanner and kernel-sandboxed step runner for GitHub Actions
(github.com)
2 points
by
electricapps
6mo ago
|
1 comments
3.
▲
by
electricapps
6mo ago
I worked on hasp after seeing the Trivy and LiteLLM PyPI-credential leak. It was clear that the failure there wasn't unique since any CI step can get compromised, and everything else in the job shares its secrets. What started as a con