forked from mirrors/probot
3f2032077b
This adds a cryptographic signature to NPM uploads to show that a upload was done by GitHub actions and not somewhere else. Such a feature should help detect malicious uploads to NPM. This feature could be extended to other repositories too. |
||
---|---|---|
.. | ||
ISSUE_TEMPLATE | ||
workflows | ||
CODEOWNERS | ||
config.yml | ||
issue_label_bot.yaml | ||
release-drafter.yml | ||
renovate.json | ||
stale.yml |