• Kairos@lemmy.today
    link
    fedilink
    English
    arrow-up
    7
    ·
    2 months ago

    Or at the very fucking least require specific versions with checksums, like golang.

    • LavenderDay3544@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      2 months ago

      I really think every package repository should be opt in and every publisher should be required to verify their identity and along with checksum verification for the downloaded files.