mirror of
https://codeberg.org/icewind/attic-action.git
synced 2026-06-03 17:44:07 +02:00
Update README.md
Co-Authored-By: Joachim Breitner <mail@joachim-breitner.de>
This commit is contained in:
parent
03b6d2e977
commit
bfb80e965d
1 changed files with 1 additions and 1 deletions
|
|
@ -64,7 +64,7 @@ Cachix auth token and signing key need special care as they give read and write
|
|||
|
||||
> Anyone with write access to a repository can create, read, and use secrets.
|
||||
|
||||
Which means all developers with push access can read your secrets and write to your cache.
|
||||
Which means all developers with push access can read your secrets and write to your cache. Furthermore, malicious code submitted via a pull request can, once merged into `master`, reveal the tokens.
|
||||
|
||||
|
||||
## Hacking
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue