Y
Hacker News
new
|
ask
|
show
|
jobs
by
philipwhiuk
13 days ago
> verified package versions
Who is doing this verification?
2 comments
cheschire
13 days ago
And then who watches the watchmen? Chains of authority can always be questioned. I think GP is suggesting that the package management platforms themselves provide the verification if they want to stay in the business of being the de facto source.
link
oneshtein
12 days ago
Those with skin in the game.
link