| 06:12 | <ljharb> | it may or may not be in the blog post, but that's very much the plan |
| 06:12 | <ljharb> | the first step is indeed the way you read it |
| 06:13 | <ljharb> | but once that's shipped, non-staged OIDC is the next to go. |
| 14:48 | <bakkot> | huh, I would be pretty shocked by that |
| 14:48 | <bakkot> | is there anywhere they've communicated that? |
| 15:54 | <rbuckton> | Apologies for missing the editor call today. I had an appointment this morning that took longer than expected. |
| 16:13 | <Michael Ficarra> | @rbuckton just take a look at https://github.com/tc39/ecma262/issues/3904 please |
| 16:13 | <ljharb> | non-2FA-based publishes cover virtually every security incident on npm; not sure why it's shocking |
| 16:13 | <ljharb> | possibly not, if i find somewhere i'll let you know |
| 16:14 | <ljharb> | altho tbf, definitelytyped needs automated publishes so i'm sure there will be some escape hatch, and i'm sure i could get tc39 included in that |
| 19:12 | <bakkot> | trusted publishing as currently conceived would equally well have prevented almost all such incidents so that is not a reason to move away from trusted publishing |
| 19:13 | <bakkot> | and lots of things need automated publishing |
| 21:25 | <ljharb> | that's definitely not accurate - a sizable chunk involved ATOs which trusted publishing doesn't stop - but we don't have to argue about it |