Hacker News new | ask | show | jobs
by hiccuphippo 2500 days ago
Any word on trying to tackle package build verification/reproductibility so users can be guaranteed that the package was built from the source code?

The problems like with rubygems from yesterday and npm a few weeks back would be gone with something like that.