[1] https://www.brandonsavage.net/github-your-single-point-of-fa...
[1] https://www.brandonsavage.net/github-your-single-point-of-fa...
It’s the code review tooling, the artifact storage & the deployment pipelines.
A distributed version of those would be awesome...
I'm not using GH actions, only Cirrus, Travis and Appveyor, which can be triggered manually if the API service is down also.
Can someone ELI5 the security implications of Ruby on Rails?
Interestingly -- the rails developers decided to put in a really horrendous hack to mitigate the common paths through which this design-flaw might lead to unexpected security outcomes ...
In a way, one could argue that the willingness to put in a horrendous hack to 'mitigate' a security flaw provides an example which demonstrates some amount of 'security reasonableness' in rails ...
In reality tho -- I think that this example serves as evidence more for the fact that rails is deeply flawed and very unlikely to be secure in practice -- for reasons of design complexity alone.