Hacker News new | past | comments | ask | show | jobs | submit login

I think it would be possible to fix it properly and without security risk by allowing pipeline authors to allowlist dependabot and/or specific forks for accessing secrets.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: