Hacker News new | ask | show | jobs
by eat_veggies 2964 days ago
I'm pretty sure all packages in the official repositories are signed:

> Official packages: A developer made the package and signed it. The developer's key was signed by the Arch Linux master keys. You used your key to sign the master keys, and you trust them to vouch for developers.

source: https://wiki.archlinux.org/index.php/Pacman/Package_signing

1 comments

I'm not talking about the binary packages.