Which is surely a strong argument for having keys that are standalone and portable across different communication media, rather than having them be coupled to accounts on particular services (or, worse, to personal information like an SSN or phone number).
(Also, the use case here is clearly much, much narrower than for age and minisign. Which is good, assuming the problem it solves is the problem you have, but should still be noted.)
Are any of the big language-specific ecosystems capable of that? (npm, crates.io, composer, PyPI, CPAN, Maven, rubygems, etc.)
For example, it would be nice to delay automatic updates of WordPress plugins and themes until after there is more than just the uploader's identity as a single point of failure guaranteeing that the update is genuine.
(Obviously the perfect way to do things given enough developer resources is to review all code yourself before installing manually, but it would be nice to improve situations where those resources are not available.)
The intention was to allow security vendors to offer code reviews of open source dependencies, and you can choose which you trust. This mechanizes Linus's Law and ensures there's an audit trail with "many eyeballs".
> The intention was to allow security vendors to offer code reviews of open source dependencies
What I care most about is just quorum publishing where multiple independent identities sign a release, so that an attacker has to compromise multiple trusted identities to execute a supply chain attack. I'm not too excited about reviews beyond that. The main thing is to upgrade collective ecosystem security by hardening automatic updates.
And, yes, there is a lot of work necessary to get WordPress to use Gossamer. I can't guarantee a deadline right now, but 2022 looks hopeful.
Huh? Unless you're signing it (in which case of course it's not deniable, it's a signature) it has no such nature.
Do you care to elaborate on those good reasons that the web of trust "failed"?