Hacker News new | past | comments | ask | show | jobs | submit login

Ok, but you didn't talk about alternatives. Why not just checksum or sign the source code?

It is important to remember that crates.io doesn't store binaries.




See also a related comment in the overall thread saying "crates.io does not host compiled artifacts. If packages on crates.io differ from their Git repository it's because of a custom pre-build step of that particular package, so a deterministic compilation toolchain won't help here."

Prove me wrong! I'm open to it.

Or be that person who is too lazy to respond with an actual comment, downvotes, and probably assumes they are right.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: