-
-
Notifications
You must be signed in to change notification settings - Fork 1.6k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Sign released Nix tarballs #17
Milestone
Comments
I agree. I can't use nix until it's cryptographically secure. |
You can build nix from source and turn off unsigned binary caches at least. |
Note that https channels fail, because they're signed by Amazon and not nixos.org (hydra's https binary cache works). I'm not saying https is of great security, but it seems better than plaintext. |
edolstra
added a commit
that referenced
this issue
Apr 25, 2017
Add :i command to install a derivation to the current profile.
aszlig
pushed a commit
to aszlig/nix
that referenced
this issue
Aug 18, 2018
Move settings to ftplugin
Closing since releases have been GPG-signed for a while. |
3 tasks
3 tasks
P-E-Meunier
pushed a commit
to P-E-Meunier/nix
that referenced
this issue
Feb 26, 2025
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Official releases should be cryptographically signed off-site.
The text was updated successfully, but these errors were encountered: