It would be great to have an automated workflow for granting one-time authorisation for CI to publish a package.
I'd like the easy of having CI sign and release on merge but with the security of local 2FA or hardware signing tokens so malicious access can be guarenteed not to be able to distribute a release.
maroon_unperson•35m ago
I'd like the easy of having CI sign and release on merge but with the security of local 2FA or hardware signing tokens so malicious access can be guarenteed not to be able to distribute a release.