haskell - Authentication for hackage downloads? -
is there way ensure authenticity of downloads hackage? far can see, there's nothing. no https hackage, , neither (strong) checksums tarballs, , neither signed.
so: how can verify authenticity of downloads hackage?
there's been significant work on new hackage server real now. matt worked on summer of code. take @ blog: http://cogracenotes.wordpress.com/
there's been thought put managing contributor logins in new , better ways, not yet verifying authenticity of downloads.
https support, on other hand, slated part of hackage 2, recall.
signed tarballs sound potentially useful, there hasn't been work done think implementing them. hackage open source, , helpful either contributions, or thought through feature proposals.
Comments
Post a Comment