| ▲ | crote 6 hours ago | |
Which is considered a Really Bad Idea because tags aren't immutable, so there's absolutely zero guarantee that it'll point to the same commit a few months from now. The GitHub Actions ecosystem found out the hard way, through some rather high-profile compromises. They hotfixed it by adding "immutable tags" to their platform, and are now working on adding a lockfile to... easily reference a commit hash. | ||
| ▲ | PunchyHamster 3 hours ago | parent [-] | |
well if you use a knife to stab your fingers that's not a knife's fault repo can also rewrite existing commit and you again won't be able to retrieve it so switching to commit IDs only lowers the level of failure somewhat | ||