3 ms·
The issues here are 1) authenticity (tampering impossible) as well as 2) distributed source control (GIT already is a best-in-class FOSS for SC). So we need to
by ClayFerguson 11y ago
The issues here are 1) authenticity (tampering impossible) as well as 2) distributed source control (GIT already is a best-in-class FOSS for SC). So we need to make GIT able to publish something that is a BlockChain-encoded item (File metadata + Content bytes, on a tree/directory structure) then we're done!
Come to think of it GIT already is able to map commits to checksums. That's practically everything that is needed. As soon as someone implements a BLOCKCHAIN GIT protocol, we're done. The problem will essentially be solved. Or in summary: Implementing a BLOCKCHAIN that stores GIT commits, along with some metadata for each commit.
BlockChain is good for finance, as well as source control is the main point here. BlockChain can store anything but the point here is redundant, verifiable storage, of all sources.
- visarga 11y agoWhat if an archived version of a module is found to contain errors or security holes? How would they fix that when the module is frozen in the BlockChain? Add a blacklist?
- X-Cubed 11y agoNo, you just publish a new release with a suitable semantic version number. The point of the blockchain is immutability of each release, not limiting a package to only ever exist as a single release.
- bergie 11y agoSomething like an Ethereum contract could be used for this. And the smart contract could also allow for deprecating/flagging bad releases as long as the transaction comes from the original author.