Hacker News new | ask | show | jobs
by philipwhiuk 13 days ago
> verified package versions

Who is doing this verification?

2 comments

And then who watches the watchmen? Chains of authority can always be questioned. I think GP is suggesting that the package management platforms themselves provide the verification if they want to stay in the business of being the de facto source.
Those with skin in the game.