[Comment removed by author]
A package archive with signed packages would probably be better.
That takes significant infrastructure and community buy-in, though.
[Comment removed by author]
A package archive with signed packages would probably be better.
That takes significant infrastructure and community buy-in, though.