• HaraldvonBlauzahn@feddit.org
    link
    fedilink
    arrow-up
    1
    ·
    9 hours ago

    I never said that GitHub was better.

    It is arguably harder to take over a package from github or Codeberg.

    You could also serve your PKGBUILD from a Gemini server (the Gemini small-web protocol, not the Google AI which is really easy to administer and secure), and sign it with a PGP key. That would be about as secure without depending on a huge US American company.