A better summary.
A better summary.
Posted Jun 11, 2026 11:11 UTC (Thu) by kleptog (subscriber, #1183)In reply to: A better summary. by LtWorf
Parent article: Eliminating long-lived credentials with trusted publishing
> Long lived upload tokens were never as problematic, to the best of my knowledge. The problem is doing uploads from a CI that runs god knows what.
So all the creds stolen in the Trivy compromise weren't a problem? Stolen Cisco code for example.
Doing uploads from CI/CD is very common. Even Debian publishes packages built from a build server. No-one has vetted all that code. Not relying on such tokens for common actions is an improvement.
