• @[email protected]
    link
    fedilink
    English
    11 year ago

    How do Linux distro’s deal with this? I feel like however that’s done, I’d like node packages to work in a similar way - “package distro’s”. You could have rolling-release, long-term service w/security patches, an application and verification process for being included in a distro, etc.

    It wouldn’t eliminate all problems, of course, but could help with several methods of attack, and also help focus communities and reduce duplication of effort.

    • style99
      link
      fedilink
      11 year ago

      Linux distros typically use a key signing party to help shore up their security concerns, but I wonder how github would go about implementing something like that.