alt.hn

3/28/2026 at 8:30:44 AM

The Comforting Lie of SHA Pinning

https://www.vaines.org/posts/2026-03-24-the-comforting-lie-of-sha-pinning/

by chillax

3/28/2026 at 8:28:25 PM

This has been a big security/UX issue with github for a while. It extends to the web interface: you can link to a specific commit under an official github repo but the contents of the README on the page will be from a malicious fork, which makes it way easier to make links look legitimate.

by rcxdude

3/28/2026 at 6:17:43 PM

TFA writes: "Late last year NPM was basically a skip fire" — is this an idiom I should know? (Something like a misfire?) Or a typo for "ship fire"? Or something else?

by quuxplusone

3/28/2026 at 8:25:31 PM

Skip is british term for dumpster.

by rcxdude

3/28/2026 at 4:22:31 PM

GitHub needs to support 'Immutable Release' on GitHub Actions, as soon as possible. Other methods are just workaround and easy to break just like example on the post.

by sh-cho

3/28/2026 at 2:48:36 PM

Wow. I did not know this. I'll bring it up in my organization.

by nathan_douglas