New top story on Hacker News: Show HN: Publish from GitHub Actions using multi-factor authentication

Show HN: Publish from GitHub Actions using multi-factor authentication
7 by varunsharma07 | 0 comments on Hacker News.
The backstory about this GitHub Action: I discussed with an open-source maintainer why they publish npm packages from their local machine and do not use CI/CD pipelines. They said publishing should require human intervention and want to continue using multi-factor authentication to publish to the npm registry. This led to building the wait-for-secrets GitHub Action. It prints a URL in the build log and waits for secrets to be entered using a browser. Once entered, the workflow continues, and secrets can be used in future steps. The latest release of "eslint-plugin-react" to the npm registry used a one-time password (OTP) from a GitHub Actions workflow! https://ift.tt/8fPRWC1...

Comments

Popular posts from this blog

Apostrophes trip up Kazakhstan's move away from Russian alphabet

Beijing 'preparing tanks at Hong Kong border', warns Trump as protesters clash with police at airport

Elizabeth Warren Takes on Democratic Rivals on Fundraising in Speech