docs(nx-dev): clarify security mention of caching policies (#31312)
Clarified language on cache poisoning protection to emphasize trusted CI branches. Removed redundant content regarding personal access tied to identity providers for simplification.
This commit is contained in:
parent
26110a6619
commit
560a53e558
@ -59,11 +59,11 @@ export function CachePoisoningProtection(): ReactElement {
|
|||||||
aria-hidden="true"
|
aria-hidden="true"
|
||||||
className="absolute left-1 top-1 h-5 w-5"
|
className="absolute left-1 top-1 h-5 w-5"
|
||||||
/>
|
/>
|
||||||
Writes only from trusted CI{' '}
|
Writes only from trusted CI branches{' '}
|
||||||
</span>
|
</span>
|
||||||
– By default, the cache artifacts are reused within each pull
|
– By default, the cache artifacts are reused within each pull
|
||||||
request. Only artifacts from verified CI pipelines can enter the
|
request. Only artifacts from trusted CI pipelines should enter
|
||||||
shared cache used by everyone. PR environments can’t poison
|
the shared cache used by everyone. PR environments can't poison
|
||||||
main.
|
main.
|
||||||
</li>
|
</li>
|
||||||
<li className="relative pl-9">
|
<li className="relative pl-9">
|
||||||
|
|||||||
@ -54,16 +54,6 @@ export function PersonalAccess(): ReactElement {
|
|||||||
Access is tied to individual user authentication
|
Access is tied to individual user authentication
|
||||||
</span>
|
</span>
|
||||||
</li>
|
</li>
|
||||||
<li className="relative pl-9">
|
|
||||||
<span className="inline font-semibold text-slate-950 dark:text-white">
|
|
||||||
<GitHubIcon
|
|
||||||
aria-hidden="true"
|
|
||||||
className="absolute left-1 top-1 h-5 w-5"
|
|
||||||
/>
|
|
||||||
Access is tied to your identity provider{' '}
|
|
||||||
</span>
|
|
||||||
— when SSO or GitHub access is revoked, cache access is too.
|
|
||||||
</li>
|
|
||||||
<li className="relative pl-9">
|
<li className="relative pl-9">
|
||||||
<span className="inline font-semibold text-slate-950 dark:text-white">
|
<span className="inline font-semibold text-slate-950 dark:text-white">
|
||||||
<LinkSlashIcon
|
<LinkSlashIcon
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user