3 ms·
Is there a language package manager that you would consider a good role model in this respect?
by wuch 11y ago
Is there a language package manager that you would consider a good role model in this respect?
- viraptor 11y agoNot the OP, but both rpm and deb have a pretty good validation story. Deb repositories (== package hashes) are gpg-signed for verification, but are usually provided over http for better caching. Nothing stops you from putting them on https either. Rpms can be signed at the package level as well.
- goodplay 11y agoI'm not aware of any language-specific package manager that gets close to having developer-package authentication, but chromium's add-on system comes pretty close as it requires add-ons be signed by the developer's private key (at least, that was the case before I stopped developing for it). I believe android's packages are secured in a similar fashion.
- eurg 11y agoIIRC Common Lisp's asdf-install did use GPG signing from developers; IIRC-again, most people disliked it. Now quicklisp exists, which does _not_ use GPG; a quick google didn't reveal any info on package authentication. Maybe a lisper can chime in?
- afshin 11y agonpm allows using git+ssh URLs which would work with ssh keys, but I'm not sure if that scales to whole organizations.