8 ms·
Yes a malicious fork will NOT be able to get a JWT just like they are not able to get any other secrets or privledges to the repo.
by chrisrpatterson 5y ago
Yes a malicious fork will NOT be able to get a JWT just like they are not able to get any other secrets or privledges to the repo.
- jffry 5y agoI was going to ask for a source, but I saw you've commented in the past that you're the GitHub Actions product manager. This looks like a great feature to help keep long-lived AWS secrets out of my builds entirely.