3 ms·
No, because then you have to trust those other people to not build the package maliciously.
by catern 5y ago
No, because then you have to trust those other people to not build the package maliciously.
- medstrom 5y agoSure, but what's the likelihood they're all compromised? Let's say 3 people have to build it (and publish the hash) before your client will download from one of them.