Have Setup-tflint as a verified GH action #221
-
Hello team, We are currently using this action, but due to some internal policy requirements to keep using it we need to have it verified. |
Beta Was this translation helpful? Give feedback.
Answered by
bendrucker
Jun 4, 2024
Replies: 1 comment 7 replies
-
Do you have evidence that GitHub verifies other small open source projects? Ultimately if you have security pressure you should probably fork the action which also sidesteps the third party ownership issue. Verification badges tell you that the action is published by a known organization but provide no actual verification of the action contents. |
Beta Was this translation helpful? Give feedback.
7 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
https://docs.github.com/en/apps/github-marketplace/github-marketplace-overview/about-marketplace-badges
We don't have a domain for the project, so this is going to be a nonstarter for now. If we launch a website with a domain for other reasons we'll do the verification but we wouldn't pursue the domain just to get verified.
You're asking nicely, but look at this from an outside perspective. In order for commercial organization to avoid paying $15/user/month for a critical tool, you're hoping for an unfunded volunteer organization to take on direct (do…