Open Menu
AllLocalCommunitiesAbout
lotide
AllLocalCommunitiesAbout
Login

GitHub Actions Has a Package Manager, and It Might Be the Worst

⁨63⁩ ⁨likes⁩

Submitted ⁨⁨4⁩ ⁨weeks⁩ ago⁩ by ⁨vogi@piefed.social⁩ to ⁨technology@lemmy.world⁩

https://nesbitt.io/2025/12/06/github-actions-package-manager.html

source

Comments

Sort:hotnewtop
  • killeronthecorner@lemmy.world ⁨4⁩ ⁨weeks⁩ ago

    Every run re-resolves from your workflow file, and the results can change without any modification to your code.

    Sounds expensive too.

    Ahhh, I get it now.

    source
  • Piatro@programming.dev ⁨4⁩ ⁨weeks⁩ ago

    R has the same problems as far as I’m aware, though it doesn’t form the core of a lot of modern CI of course!

    source
    • festus@lemmy.ca ⁨4⁩ ⁨weeks⁩ ago

      R (largely and by default) relies on CRAN, and they are extremely selective about what packages they accept, including testing new package versions against downstream packages before publishing an update, etc. That largely mitigates many of the concerns of some random 10 layer deep dependency getting swapped for something malicious.

      source