You must log in or register to comment.
When are we gonna say “'nuffs 'nuff” and require MFA to publish packages EVEN IF ITS CI/CD for main line releases?
Scary.
Any tutorial on how to use those “dev containers” mentioned in the article? I feel this is the only way forward. it doesn’t remove the risk of deploying malware to production server but it significantly reduce it. it also eliminate the risk of infecting developer’s own PC

