-
Notifications
You must be signed in to change notification settings - Fork 45
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
packages.json: support (require?) SHA in addition to version #55
Comments
Sounds like a good idea. |
Adding this here as a related consideration: https://theupdateframework.github.io/ Since hackage implements this, it might not be too hard to steal code from them at some future point. https://github.com/haskell/hackage-security This might not be applicable given that |
@Pauan thanks. Good to see I'm not the only one with this concern. I will do some reading and have a think. |
Requiring a hash in addition to the version tag would be a cheap additional layer of security. As it stands, a package author could maliciously amend a tag in their git repo, no?
The text was updated successfully, but these errors were encountered: