Closes tab
Closes tab
Distributing unsigned software, then asking users to blindly execute it, is simply irresponsible.
In that case, you can simply stick to the commit hash you read the source code from.
https://raw.githubusercontent.com/nanovms/ops/0b7e8bb9e56767...
Download first, review, then execute.
Or even better, download, verify signatures from multiple reputable people, optionally review, then execute.
Isn't the commit and its hash immutable?
2. None of your artifacts or build script are signed by you (third party signs by apple are pointless)
3. Builds have no evidence of being reproducible, or anyone having reproduced and counter signed them.
Compare to say the Bitcoin or Monero processes that have multiple people build and sign every release so it is easy to trust there were no SPOFs.
See Arch Linux, Debian, Guix, Stagex