3 ms·
IMO just signing packages is a weak form of trust. Even without potentially using Sigstore, does WAPM now let you lock based both on the versions of dependencie
by no_circuit 5y ago
IMO just signing packages is a weak form of trust. Even without potentially using Sigstore, does WAPM now let you lock based both on the versions of dependencies, as well as the hash of their contents? I didn't see any mention of lock files with hashes anywhere.