logoalt Hacker News

E39M5S62today at 1:46 AM1 replyview on HN

Same as anything else installed as a binary package - you trust the people packaging/providing the binary. If you don't, build it yourself. The source is publicly available.


Replies

pabs3today at 2:27 AM

Or you build it yourself and verify you got the same checksum.

https://reproducible-builds.org/