Hacker News new | ask | show | jobs
by asvitkine 804 days ago
How would that even work? Are distros expected to code their own alternative versions of open source libraries where they can't get the maintainers to send their IDs? Or what stops from forged IDs being used?