Hacker News new | ask | show | jobs
by captn3m0 3514 days ago
Not a very good idea, for the very reasons you point out. Signed releases with public keys, as conradev points out below is the far better approach.