Damus
Max · 22w
A new npm / package registry signed with nostr keys Inspired by nostr:nprofile1qy88wumn8ghj7mn0wvhxcmmv9uq3uamnwvaz7tmwdaehgu3dwp6kytnhv4kxcmmjv3jhytnwv46z7qpqaljazgxlpnpfp7n5sunlk3dvfp72456x6nezjw4s...
aljaz profile picture
Signing with nostr keys vs gpg or whatever else wouldn't make much difference in case of compromise tho, unless you could really ensure that all package signing keys are using a hardware signer and that the key never left the signer (think hsm/hardware wallet) so that just a compromise of devs machine wouldn't be enough, you would also need physical access

Or using multisig approach with multiple parties needing to sign (and some of them not being known) could prevent some of it
1
Max · 22w
True - that's a different problem and multisig is a good starting point to solve that. But you can use nostr web of trust for reputation! I see as nostr pgp with actual adoption