Running an .exe from GitHub is a leap of faith. Here is how I keep things secure.
GitHub can now block and alert you of pull requests that introduce new dependencies impacted by known supply chain vulnerabilities. This is achieved by adding the new Dependency Review GitHub Action ...