Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
andycaine
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
3 ms
·
1.
▲
by
andycaine
1y ago
That's great - PGP signing works for you in your org. But the fact is it hasn't worked for package repos like PyPi, and it won't for npm, because in a distributed, low-trust ecosystem like npm, you can't easily bind iden
2.
▲
by
andycaine
1y ago
Some of the reservations around GPG and PKI are understandable. GPG signing clearly works for OS package managers where there is more control, but it's been a failure on PyPi, RubyGems and Maven. I'd love to see npm adopt keyless