• chaospatternsOP
    link
    fedilink
    English
    arrow-up
    20
    ·
    24 days ago

    Here’s a good reason why you should pin to specific sha hashes, not just release versions.

  • bleistift2@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    7
    ·
    23 days ago

    PrOtEcTiNg ThE sUpPlY cHaIn Is ImPoRtAnT tO uS. tHeReFoRe We NoW fOrCe 2Fa On YoU.

    • StripedMonkey@lemmy.zip
      link
      fedilink
      arrow-up
      1
      ·
      6 days ago

      2fa isn’t a panacea and won’t solve every problem. It does help though. Why do you think supply chain integrity isn’t something they care about?