• quick_snail@feddit.nl
      link
      fedilink
      English
      arrow-up
      9
      arrow-down
      1
      ·
      1 day ago

      A package manager that uses cryptographic signatures. Apt had this since 2005 iirc. Use apt.

        • quick_snail@feddit.nl
          link
          fedilink
          English
          arrow-up
          2
          ·
          22 hours ago

          Packages are reviewed by package maintainers.

          Humans are required to solve a malicious insider. But most supply chain vulns of these shitty software dependency managers were resolved decades ago by freely available cryptography

    • grandma@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      22
      ·
      1 day ago

      Easy, just vendor all your dependencies! Can’t have a supply chain attack if you are the supply chain.