• quick_snail@feddit.nl
      link
      fedilink
      English
      arrow-up
      0
      ·
      12 days ago

      A package manager that uses cryptographic signatures. Apt had this since 2005 iirc. Use apt.

        • quick_snail@feddit.nl
          link
          fedilink
          English
          arrow-up
          0
          ·
          9 days ago

          Oh boy. Maven is like the only language dependency manager that does signing tho!

          You don’t need to use apt for java. Just use maven :)

        • quick_snail@feddit.nl
          link
          fedilink
          English
          arrow-up
          0
          ·
          12 days ago

          Packages are reviewed by package maintainers.

          Humans are required to solve a malicious insider. But most supply chain vulns of these shitty software dependency managers were resolved decades ago by freely available cryptography

    • grandma@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      0
      ·
      12 days ago

      Easy, just vendor all your dependencies! Can’t have a supply chain attack if you are the supply chain.