You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Corepack currently depends on the security of HTTPS. Projects that want stronger guarantees should optionally be allowed to configure an integrity hash for the downloaded package manager. Obviously this would only be possible when configuring an exact version rather than a range.
Integrity hashes for the default known-good versions should be included in Corepack, so that users get the strongest security guarantees by default.
(Related to #10, but without requiring modifications to the registry or the package managers.)
The text was updated successfully, but these errors were encountered:
Corepack currently depends on the security of HTTPS. Projects that want stronger guarantees should optionally be allowed to configure an integrity hash for the downloaded package manager. Obviously this would only be possible when configuring an exact version rather than a range.
Integrity hashes for the default known-good versions should be included in Corepack, so that users get the strongest security guarantees by default.
(Related to #10, but without requiring modifications to the registry or the package managers.)
The text was updated successfully, but these errors were encountered: