Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Verify that the repository inside the pubspec.yaml actually matches the uploaded code #8582

Open
benthillerkus opened this issue Feb 21, 2025 · 1 comment

Comments

@benthillerkus
Copy link

benthillerkus commented Feb 21, 2025

Looking through unrelated issues here on the tracker, it seems that at multiple times in the past this was being worked on, but I couldn't find an actual ticket for it.

There are some pitfalls to this, when it comes to generated code, but I think for most packages it should be no problem?

@sigurdm
Copy link
Contributor

sigurdm commented Feb 27, 2025

Yes we want to do something along these lines at some point.

We might want to do this as SALSA attestations and signatures instead of us validating the code. (https://slsa.dev/attestation-model#model-and-terminology)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants