Hacker News new | ask | show | jobs
by enatik 1858 days ago
Currently there’s have no way of generating checksums or cryptographic signatures as Pakkly doesn’t enforce any structure on apps. They are delivered straight from GitHub releases so the security considerations are the same as downloading from a browser.

I’m developing a CLI tool to allow signing and notarizing your apps and the installer itself. Hopefully that will alleviate some of the concerns you have.

The third-party service angle is understandable, but I’m not certain how it’s any different from any other third-party service.