4 ms·
Client implementations typically need to be deeply integrated with the host PL/OS but I think we can create a shared package registry with a protocol that sits
by tmpfs 5y ago
Client implementations typically need to be deeply integrated with the host PL/OS but I think we can create a shared package registry with a protocol that sits on top of IPFS.
A single tool for publishing to the registry would push the package to IPFS, get the returned CID (hash of the package) and store the hash with some package meta data in a blockchain. Storing the hash in a blockchain would provide confidence the package has not been tampered with assuming no 51% attack and that client implementations always verify the hash against the package bytes. By making the hash immutable and linked to the content address of the package we have more confidence in the integrity of our packages.
Then we add an HTTPS bridge so that client implementations can easily migrate to consuming packages via this new distributed registry.
I am exploring this now so if anyone is interested in this kind of distributed language-agnostic package registry drop me a line at muji [at] tmpfs.org.
- tadfisher 5y agoNix is already most of the way there with content-addressed packages. An IPFS project is also in the works using this feature. A blockchain is unnecessary because reproducible packages can be checked with `nix build --rebuild` and stores are signed by default. A bridge is unnecessary because Nix wraps language-specific package managers when building and does not allow network access in its sandbox.
- tmpfs 5y agoThanks, i will take a closer look at nix!