• Kairos@lemmy.today
    link
    fedilink
    English
    arrow-up
    7
    ·
    14 hours ago

    Or at the very fucking least require specific versions with checksums, like golang.

    • LavenderDay3544@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      3 hours ago

      I really think every package repository should be opt in and every publisher should be required to verify their identity and along with checksum verification for the downloaded files.