PSA: remember it's important to lock github actions to an immutable commit hash so that the node.js script that fetches and executes a shell script from a random attacker-controlled URL cannot change ๐Ÿ’ช

0

If you have a fediverse account, you can quote this note from your own instance. Search https://hachyderm.io/users/fasterthanlime/statuses/114357702940766207 on your instance and quote it. (Note that quoting is not supported in Mastodon.)