(no title)
raesene4 | 10 years ago
Ideally the developer would sign before publishing and the consumer could check the signature to validate before using.
Whilst not a silver bullet this is a kind of essential part of a secure package management solution.
pvg|10 years ago
raesene4|10 years ago
What repositories were you thinking of that do require that?