Hacker News new | ask | show | jobs
by oneshtein 14 days ago
Why not to create a separate list of verified package versions for most popular packages, AKA «stable» channel?

Use stable channel for typical packages, use bleeding edge channel for some specific packages only.

1 comments

> verified package versions

Who is doing this verification?

And then who watches the watchmen? Chains of authority can always be questioned. I think GP is suggesting that the package management platforms themselves provide the verification if they want to stay in the business of being the de facto source.
Those with skin in the game.