logoalt Hacker News

rishabhaioveryesterday at 2:02 PM0 repliesview on HN

I was working with the assumption in this model the attestation is signed by ephemeral keys (OIDC) which would reveal the bad actor or give breadcrumbs. Enough to reduce incentives to hijack packages.