We discovered early on with RM that one needs to protect its output from the unwary. Those with group write privilege to the disk could modify builds. Alex then write-protected the output (presumably turned off the group write bit). We should do something similar to protect the files the pipeline creates.

  • No labels