Hacker News new | ask | show | jobs
by CiPHPerCoder 3162 days ago
> Maybe it could check the signature everytime one downloads the bundle?

Yes, that's probably the direction we're going to go.

> So downstream developers+admins need to set pretty liberal file permissions? (Or perhaps dig-up a way to use an alternative data directory?) Might be useful for the docs mention this.

That's a good point. Another developer indicated they were writing a pull request to add composer post-install hooks, and I could easily add one that chmods this directory.