logoalt Hacker News

dcrazyyesterday at 6:38 AM0 repliesview on HN

Sorry, attestation is the goalpost. The community wants certainty that the package was published by a human with authority, and not just by someone who had access to an authority’s private keys. That is what distinguishes attestation from authentication or authorization.