Hello Donald & all, GNU Guix uses signed tags and commits on its Git repository, which is where package definitions are, and release files on alpha.gnu.org are also GPG-signed by one of the maintainers.
Pre-built binaries for packages, which are opt-in, are also signed. It’s up to the user to decide whether or not to trust binaries provided by, say, hydra.gnu.org: https://www.gnu.org/software/guix/manual/html_node/Substitute-Server-Authorization.html Most of our package builds are bit-reproducible so users can “challenge” servers that provide binaries—i.e., check whether they provide the same binaries as other servers or the same as those they built locally: https://www.gnu.org/software/guix/manual/html_node/Invoking-guix-challenge.html Ludo’.
signature.asc
Description: PGP signature
