• quick_snail@feddit.nl
      link
      fedilink
      English
      arrow-up
      8
      ·
      6 hours ago

      A package manager that uses cryptographic signatures. Apt had this since 2005 iirc. Use apt.

        • quick_snail@feddit.nl
          link
          fedilink
          English
          arrow-up
          2
          ·
          3 hours ago

          Packages are reviewed by package maintainers.

          Humans are required to solve a malicious insider. But most supply chain vulns of these shitty software dependency managers were resolved decades ago by freely available cryptography

    • grandma@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      20
      ·
      13 hours ago

      Easy, just vendor all your dependencies! Can’t have a supply chain attack if you are the supply chain.