|
|
|
|
|
by swarfield
1241 days ago
|
|
Using SHA hashes when building guarantees that the code that you are building is what you think it is. How else would you verify dependencies like this, GPG signatures would have the same issue if you change the underlying bits. |
|