|
|
|
|
|
by lrvick
280 days ago
|
|
The most important is just having authors sign their code and packages, and verifying code that is signed on download, like every sane Linux distro goes. Except NPM rejected this over and over going back to 2013. https://github.com/npm/npm/pull/4016 |
|
I'd love to see npm adopt keyless signing like PyPi are doing with https://peps.python.org/pep-0740/.