logoalt Hacker News

frabcustoday at 7:16 AM1 replyview on HN

Have any kind of provenance. eg like Debian has for 30 years. Key signing in person etc


Replies

tpetrytoday at 8:51 AM

That has also been implemented recently. With staged publishing the author must verify a new release with 2FA so automated attacks dont work anymore. Some human in the loop must verify a release.