Hacker News new | ask | show | jobs
by socrates667 2603 days ago
They can create a special kind of Authentic GitHub signing that guarantees that the source you see is responsible for the binary being downloaded.