alitheg commented on issue #1358:
URL: 
https://github.com/apache/tooling-trusted-releases/issues/1358#issuecomment-4925566099

   This has been implemented to prevent the SSH-issuance being carried out more 
than once (using jti). By design, we do allow the reuse of the token itself - 
you can perform multiple ATR actions in one workflow with one token, but there 
should be no need for a second SSH key. If we need to tighten this more in 
future, we could require every API call to issue a *new* OIDC JWT.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to