@ocdtrekkie Yes but think about it… (not that I’m defending Google™ here), if you were to implement this yourself, you would have to separate out the “fetching a package” vs. “verifying the integrity of a package” right? – Put another way, you wouldn’t trust the checksum/integrity of a package from the source you got the package from (in this case Git) woul ... ⌘ Read more
@ocdtrekkie Yes but think about it… (not that I’m defending Google™ here), if you were to implement this yourself, you would have to separate out the “fetching a package” vs. “verifying the integrity of a package” right? – Put another way, you wouldn’t trust the checksum/integrity of a package from the source you got the package from (in this case Git) woul ... ⌘ Read more