GitHub Actions Has a Package Manager, and It Might Be the Worst https://lobste.rs/s/zbqvyu #security
https://nesbitt.io/2025/12/06/github-actions-package-manager.html
If you have a fediverse account, you can quote this note from your own instance. Search https://mastodon.social/users/lobsters/statuses/115673885057378676 on your instance and quote it. (Note that quoting is not supported in Mastodon.)