-
Notifications
You must be signed in to change notification settings - Fork 10
Open
Description
crates.io currently lacks a number of fairly basic security features, such as requiring signatures from several maintainers to issue a package release.
Designing a solution for this from scratch or gradually patching for more and more stuff sound like dubious undertakings. Fortunately, The Update Framework provides a fairly comprehensive solution that is not overly tedious for crate maintainers. A Rust implementation is in progress.
Discussion on crates.io issue tracker: rust-lang/crates.io#75
Metadata
Metadata
Assignees
Labels
No labels