New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Verify authenticity of signed payload #48

merged 4 commits into from Dec 20, 2018


None yet
2 participants
Copy link

ericmj commented Dec 20, 2018

No description provided.

@ericmj ericmj requested a review from wojtekmach Dec 20, 2018

@wojtekmach wojtekmach merged commit 009d4de into master Dec 20, 2018

2 checks passed

continuous-integration/travis-ci/pr The Travis CI build passed
continuous-integration/travis-ci/push The Travis CI build passed

@wojtekmach wojtekmach deleted the emj/verify-registry-origin branch Dec 20, 2018

wojtekmach added a commit to hexpm/hex that referenced this pull request Dec 20, 2018

@@ -31,21 +31,21 @@ Get all package versions from repository:
> hex_repo:get_versions(Config).
{ok, {200, ...,
#{packages => [

This comment has been minimized.


wojtekmach Dec 30, 2018


@ericmj to recap, previously we had:

> hex_repo:get_versions(Config)
{ok, {200, _, #{packages => Packages}}}

now we have:

> hex_repo:get_versions(Config)
{ok, {200, _, Packages}}

which means we'd no longer be able to associate any "metadata" with the versions resource in a backwards compatible way (adding new keys to the return map). I think that's OK, I can't think of anything we'd use it for, but just mentioning it. Thoughts?

This comment has been minimized.


ericmj Dec 30, 2018

Author Member

I think it's better this way, the other "metadata" wasn't really documented in the first place, right?

This comment has been minimized.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment