GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    ✧✦Catherine✦✧ (whitequark@mastodon.social)'s status on Saturday, 11-Oct-2025 07:16:22 JST ✧✦Catherine✦✧ ✧✦Catherine✦✧

    oh eat my entire ass, npm

    once they implement that i'm just going to put username and password into the github publishing workflow. i am *not* going to manually swap tokens, not every 7 days, not every 90

    In conversation about 4 months ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/115/352/178/217/045/409/original/6f8914e54b5f0d12.png
    • Rich Felker repeated this.
    • Embed this notice
      ✧✦Catherine✦✧ (whitequark@mastodon.social)'s status on Saturday, 11-Oct-2025 07:18:49 JST ✧✦Catherine✦✧ ✧✦Catherine✦✧
      in reply to
      • J. "Henry" Waugh

      @jhwgh1968 upgrading to passkeys. this is actually probably strictly better so i'm chill about it

      In conversation about 4 months ago permalink
    • Embed this notice
      J. "Henry" Waugh (jhwgh1968@chaos.social)'s status on Saturday, 11-Oct-2025 07:18:50 JST J. "Henry" Waugh J. "Henry" Waugh
      in reply to

      @whitequark I'm trying to figure out line 2

      They're not allowing TOTP anymore? Are they downgrading to SMS or some nonsense?

      In conversation about 4 months ago permalink
    • Embed this notice
      Mike Mattice (mmattice@mastodon.social)'s status on Saturday, 11-Oct-2025 07:30:52 JST Mike Mattice Mike Mattice
      in reply to
      • J. "Henry" Waugh

      @whitequark @jhwgh1968 it'd be nice if GitHub had a way to generate a passkey and enroll it into npm. But this is dumb af without that.

      In conversation about 4 months ago permalink
    • Embed this notice
      ✧✦Catherine✦✧ (whitequark@mastodon.social)'s status on Saturday, 11-Oct-2025 07:46:55 JST ✧✦Catherine✦✧ ✧✦Catherine✦✧
      in reply to
      • John

      @jpab yes, I'm setting this up right now in fact. still a shitload of busywork but not as bad as the initial impression. (I use OIDC publishing with PyPI already)

      In conversation about 4 months ago permalink
    • Embed this notice
      John (jpab@mastodon.gamedev.place)'s status on Saturday, 11-Oct-2025 07:46:56 JST John John
      in reply to

      @whitequark can't you use the "Trusted Publisher" thing if you're publishing from GitHub?

      You configure npm account to allow publishing from a particular GitHub project & workflow and then there's some OIDC auth dance between GitHub and npm which avoids the need to put an npm token in a GitHub actions secret.

      In conversation about 4 months ago permalink
    • Embed this notice
      ✧✦Catherine✦✧ (whitequark@mastodon.social)'s status on Saturday, 11-Oct-2025 07:47:30 JST ✧✦Catherine✦✧ ✧✦Catherine✦✧
      in reply to

      good news: you can use Trusted Publishing to avoid dealing with the tokens

      bad news: do you think github's own instructions for how to set this shit up on github work? yes? hahaha no of course they fucking don't imagine anybody involved in this mess doing their job well

      In conversation about 4 months ago permalink
      Rich Felker repeated this.
    • Embed this notice
      ✧✦Catherine✦✧ (whitequark@mastodon.social)'s status on Saturday, 11-Oct-2025 07:51:50 JST ✧✦Catherine✦✧ ✧✦Catherine✦✧
      in reply to

      i should bill GitHub for my time

      In conversation about 4 months ago permalink
    • Embed this notice
      jcoglan (jcoglan@mastodon.social)'s status on Saturday, 11-Oct-2025 07:54:17 JST jcoglan jcoglan
      in reply to

      @whitequark please tell me I don't have to use github actions for this. my current workflow is the 'npm publish' command locally and entering a totp code

      In conversation about 4 months ago permalink
    • Embed this notice
      ✧✦Catherine✦✧ (whitequark@mastodon.social)'s status on Saturday, 11-Oct-2025 08:23:33 JST ✧✦Catherine✦✧ ✧✦Catherine✦✧
      in reply to
      • jcoglan

      @jcoglan you'll have to keep rotating tokens

      In conversation about 4 months ago permalink
    • Embed this notice
      mcc (mcc@mastodon.social)'s status on Saturday, 11-Oct-2025 08:25:00 JST mcc mcc
      in reply to
      • jcoglan

      @jcoglan @whitequark wait so if i want to publish using totp on npm in future do i need to sign up for totp tokens now. will that force me to use totp afterward or can i just get something registered

      In conversation about 4 months ago permalink
    • Embed this notice
      ✧✦Catherine✦✧ (whitequark@mastodon.social)'s status on Saturday, 11-Oct-2025 08:25:00 JST ✧✦Catherine✦✧ ✧✦Catherine✦✧
      in reply to
      • mcc
      • jcoglan

      @mcc @jcoglan i _think_ you can still make a "granular" token valid until 2038

      In conversation about 4 months ago permalink
    • Embed this notice
      ✧✦Catherine✦✧ (whitequark@mastodon.social)'s status on Tuesday, 21-Oct-2025 08:07:25 JST ✧✦Catherine✦✧ ✧✦Catherine✦✧
      in reply to
      • J. "Henry" Waugh
      • Demi Marie Obenour

      @alwayscurious @jhwgh1968 keepassx has an extension for at least chrome

      In conversation about 4 months ago permalink
    • Embed this notice
      Demi Marie Obenour (alwayscurious@infosec.exchange)'s status on Tuesday, 21-Oct-2025 08:07:26 JST Demi Marie Obenour Demi Marie Obenour
      in reply to
      • J. "Henry" Waugh

      @whitequark @jhwgh1968 which browsers support passkeys on Linux?

      In conversation about 4 months ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.