Russ Cox about 1 month ago
Build deps get attention largely because they are easily computed. Other relevant dep graphs that are harder to compute are ignored.
The GitHub Actions graph is clearly relevant to attacks and should be easily computable from public repos.
What are the 'is-even's of GitHub Actions? Who owns them?