| ▲ | rishabhaiover 5 hours ago | |||||||
Why can't package managers enforce attestations backed by a transparent log for each commit made to a public repository? | ||||||||
| ▲ | hashstring 5 hours ago | parent | next [-] | |||||||
They can, but what does it solve? If a malicious package gets pushed, who or what is the equivalent of the CA that you are you going to nuke? | ||||||||
| ||||||||
| ▲ | dboreham 4 hours ago | parent | prev [-] | |||||||
They can but that wasn't done in this case and isn't commonly done for various reasons. | ||||||||