Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> no need for compliance enforcement stuff

I find github actions works very well for compliance. The ability to create attestations makes it easy to enforce policies about artifact provenance and integrity and was much easier to get working properly compared to my experience attempting to get jenkins to produce attestations.

https://docs.github.com/en/actions/security-for-github-actio...

https://docs.github.com/en/actions/security-for-github-actio...

What was your issue with it?



They also work very well to leak all your secrets and infect people who download your software from pypi :D




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: