Is there a trustable, out-of-band way for users to get the hash? How?
There's a real vulnerability where users get a compromised package and a matching hash from the same compromised repository.
There's a real vulnerability where users get a compromised package and a matching hash from the same compromised repository.
This is an idiom borrowed from certificate transparency. You kind of want the badly signed certs to be recorded, as they can be monitored and audited for. Everything is out in the open in the plain light of day.