Skip to content

Consider enabling immutable releases #120

@zsol

Description

@zsol

Both this repo and https://github.com/facebook/install-dotslash uses mutable GitHub releases currently, which allow maintainers to change a release after it's been published (including creating/modifying/deleting release assets).

This is a supply chain risk for anyone using these repos' releases.

Please enable immutable releases on these repos and publish a new release.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions