Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
captn3m0
4 months ago
|
parent
|
context
|
favorite
| on:
Postmortem: TanStack NPM supply-chain compromise
I’m paranoid but I never authenticate the GitHub CLI - there should be no tokens lying around on my system. If needed, I have some scoped PATs in pass, which I can source as env variables. Git Pushes happen over SSH with Yubikey.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: