New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Signing #165
Comments
Using bundled prebuilds this becomes npm's problem as we don't need to download / checksum anything. npm does that for us |
I don't think signing is on npms roadmap. Checksumming might be, but not signing. Context node-forward/discussions#29 |
npm already does checksumming when installing. i don't think we'd gain anything by signing if npm doesn't do it, unless i'm mistaken what you mean. |
|
I mean: with the prebuilds bundled inside the npm tarball I don't see what we gain by signing the binaries. It's still gonna execute JS code downloaded from npm that isn't signed. |
good call. i guess if npm doesnt support signing we're screwed |
In addition to #157 it'd be cool to have signing built in to prebuild, maybe using the format from https://jedisct1.github.io/minisign/
The text was updated successfully, but these errors were encountered: