Hacker News new | ask | show | jobs
by parenthephobia 3084 days ago
I think package URIs should include a secure hash of their contents.

Although you won't get updates without asking for them - I'm not sure that's a bad thing - you can be assured that you'll either get the package you were expecting or no package at all.