Conversation

This Tweet was deleted by the Tweet author. Learn more
This Tweet was deleted by the Tweet author. Learn more
This Tweet was deleted by the Tweet author. Learn more
That's true, but I have the (perhaps wrong) impression that most people would take handing over control of a signing key more seriously than a repository on GitHub or a package on npm. It very explicitly involves trust / security so it's harder to ignore what should be obvious.
2
1
Show replies
I don't mean a warning flag but rather something like a public log of added collaborators and requiring the owner to write a summary of why they're adding them just like they do for commit messages. Not entirely sure but I don't think people watching the repo even get notified.
1
Show replies