Hacker News new | ask | show | jobs
by sixbrx 4060 days ago
He addresses this issue - see the part about using hashes for everything so neither names nor lib versions matter, only the contents do, identified by hashes.