• piccolo@sh.itjust.works
    link
    fedilink
    arrow-up
    1
    ·
    edit-2
    2 hours ago

    The point of signing software is to ensure the software was not tampered from the publisher. Linux package managers solve this by comparing a gpg key from the publisher with the software’s. There is no need for a corporate giant to “vet” software.