<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><description>nextjs @vercel.com, @react.dev at night, @testing-library.com core | testing + a11y first | he/him</description><link>https://bsky.app/profile/sebbie.dev</link><title>@sebbie.dev - Sebastian Silbermann </title><item><link>https://bsky.app/profile/sebbie.dev/post/3mv4bosl2hc2o</link><description>Almost as many contributors as 19.0.0. Lots of bug fixes from the community in there!&#xA;&#xA;[contains quote post or other embedded content]</description><pubDate>09 Sep 2026 19:32 +0000</pubDate><guid isPermaLink="false">at://did:plc:5nhpcpbpk7lfwc6jsjd4pdpc/app.bsky.feed.post/3mv4bosl2hc2o</guid></item><item><link>https://bsky.app/profile/sebbie.dev/post/3mlnx33kol222</link><description>I personally would recommend reviewing actions/checkout with a custom ref input instead. actions/checkout is the way to escape trust boundaries. In pull_request_target events that&#39;s fork -&gt; upstream. But in workflow_dispatch events actions/checkout allows running in protected GH environments.&#xA;&#xA;[contains quote post or other embedded content]</description><pubDate>12 May 2026 13:58 +0000</pubDate><guid isPermaLink="false">at://did:plc:5nhpcpbpk7lfwc6jsjd4pdpc/app.bsky.feed.post/3mlnx33kol222</guid></item></channel></rss>