|
|
|
|
|
by eric_bullington
4387 days ago
|
|
Even if you do verify the integrity of the package, then you still can't know for absolute certain that the package maintainer hasn't somehow exposed their private key or been otherwise compromised. You have to trust them. |
|