Skip to content

Comment on GitHub Actions is the weakest linkparent

Comments

Better to treat it as a dependency still, but audit each new commit/release as it comes in, and pin to the exact last commit id that you verified.

Yes, but no one audits new dependencies versions usually. Only Release Notes mostly.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.