alitheg commented on issue #1358: URL: https://github.com/apache/tooling-trusted-releases/issues/1358#issuecomment-4925566099
This has been implemented to prevent the SSH-issuance being carried out more than once (using jti). By design, we do allow the reuse of the token itself - you can perform multiple ATR actions in one workflow with one token, but there should be no need for a second SSH key. If we need to tighten this more in future, we could require every API call to issue a *new* OIDC JWT. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
