Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
teacup50
on Feb 11, 2015
|
parent
|
context
|
favorite
| on:
Just-in-time packager for GitHub repositories
Yes, we verify signatures at our middleware repository cache.
pron
on Feb 11, 2015
[–]
Really? Impressive! Where do you get the public keys? Most projects hosted on Maven Central don't publish them on their website.
teacup50
on Feb 12, 2015
|
parent
[–]
http://blog.sonatype.com/2009/04/nexus-133-introduces-automa...
pron
on Feb 12, 2015
|
root
|
parent
[–]
But unless the signers have a public certificate, or publish their public keys on their website (which you need to obtain manually), the signatures on Maven Central can be just as fake as the artifacts.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: