logoalt Hacker News

embedding-shapetoday at 5:27 PM1 replyview on HN

Any developers worth their salt has build scripts turned off everywhere at this point, and manually build the packages they need it for, or manually whitelisted. It may save time, but as others mentioned, shipping binary blobs in a opaque way is a great way of making people avoid your project.


Replies

threatofraintoday at 7:15 PM

Just have a seamless process between author and user for signing and verifying builds.

show 1 reply