Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It appears that there is a maintainer approval process on nixpkgs prs? Am I wrong about that, or did you mean upstream approval process?

Can you expand on the issue with code signing?




The current process simply assumes Github credentials can never be stolen, and ignores countless cases where exactly that has happened.

See rejected RFC for more details: https://github.com/NixOS/rfcs/pull/34




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: