I was looking at CI options for GitHub and the actions available for scp'ing a file:

github.com/marketplace?type=ac

This is Russian roulette. I tried auditing three of these options and either they use some shifty copy of openssh or I just can't trust all of their indirection layers. How do people trust these things?!

Sign in to participate in the conversation
CleverLibre Social

CleverLibre Social is an inclusive social instance for open discussion, learning, and community.
All cultures welcome.
Hate speech and harassment strictly forbidden.