OverviewExploreTrending
Nostr Archives
OverviewExploreTrending
semisol13d ago
Every package manager under the sun already does signature verification.
💬 2 replies

Thread context

Replying to: cd9dd6de9fe7…

Replies (2)

franzap13d ago
You can do better
0000 sats
ChipTuner13d ago
Yeah this. I think the OP was a bit much. Yes the user could take verification into there own hands like we do, but most wont, so repos, repo maintainers and distributions already (at least the major modern repos) by default already have pretty good signature verification with a pretty user friendly way of verifying and installing keys if needed. 3rd party repos are often signed if users want to get signed packages from the devs too.
0000 sats