Hacker News new | ask | show | jobs
by toast0 2424 days ago
You would need to certify each signed release. Most likely, you wouldn't make a signed release for each PR, because of the time and expense involved, until you got to the point were changed were few and far between.