> Without a web of trust (sigh), a PKI (ugh), or some other mechanism to tie identities to trust metrics, this is essentially a complicated, very expensive, and fragile version of the shasum check npm already has.
The stance was without an agreed upon way of trusting public keys, you don't get any additional protection beyond shasum. Isn't that true?
The stance was without an agreed upon way of trusting public keys, you don't get any additional protection beyond shasum. Isn't that true?