jelly-beam/otp-macos

Add disclaimer about usage in README

Closed this issue · 2 comments

While our action is dead simple, it uses other actions and tools, and what's more there's github itself. TL;DR We try our best to ensure the binaries released are safe, but there is a chain of trust at work here. Use at your own risk, and do xyz (e.g., verify the binary using the sha sum that went along with it, etc.) to help protect yourself.

Yeah, I think a disclaimer is good. This, tied with:

  1. the community's 👀
  2. a SECURITY.md
  3. a LICENSE
  4. GitHub Actions secbot
  5. our reading of the hardening rules and implementing them

should already be good steps in the right direction.

I'd like to deal with the "removal of 3rd party" before, though, so we wanna have the best disclaimer possible (and updated too).