Issue migrated from https://api.github.com/repos/zero-os/0-hub/issues/6, opened by @yveskerwyn
In order to prevent attackers to publish infected flist Dbs
Signed FlistDBs are more secure, trustworthy
We should support this from day one... Docker only introduced this feature with Docker Content Trust later, it automatically signs and verifies the signature of a publisher.
Also the Docker alternative rkt has this capability since inception, signature verification is done by default.
Issue migrated from https://api.github.com/repos/zero-os/0-hub/issues/6, opened by @yveskerwyn
In order to prevent attackers to publish infected flist Dbs
Signed FlistDBs are more secure, trustworthy
We should support this from day one... Docker only introduced this feature with Docker Content Trust later, it automatically signs and verifies the signature of a publisher.
Also the Docker alternative rkt has this capability since inception, signature verification is done by default.