06:12
<ljharb>
it may or may not be in the blog post, but that's very much the plan
06:12
<ljharb>
the first step is indeed the way you read it
06:13
<ljharb>
but once that's shipped, non-staged OIDC is the next to go.
14:48
<bakkot>
huh, I would be pretty shocked by that
14:48
<bakkot>
is there anywhere they've communicated that?
15:54
<rbuckton>
Apologies for missing the editor call today. I had an appointment this morning that took longer than expected.
16:13
<Michael Ficarra>
@rbuckton just take a look at https://github.com/tc39/ecma262/issues/3904 please
16:13
<ljharb>
non-2FA-based publishes cover virtually every security incident on npm; not sure why it's shocking
16:13
<ljharb>
possibly not, if i find somewhere i'll let you know
16:14
<ljharb>
altho tbf, definitelytyped needs automated publishes so i'm sure there will be some escape hatch, and i'm sure i could get tc39 included in that
19:12
<bakkot>
trusted publishing as currently conceived would equally well have prevented almost all such incidents so that is not a reason to move away from trusted publishing
19:13
<bakkot>
and lots of things need automated publishing
21:25
<ljharb>
that's definitely not accurate - a sizable chunk involved ATOs which trusted publishing doesn't stop - but we don't have to argue about it