Angius Posted Tuesday at 06:45 PM Report Posted Tuesday at 06:45 PM Mod DB should support mod provenance, that is a way to attest that the mod we download is build from the exact code on Github/Gitab/Codeberg/whatever. A build function should exist that builds the code and uploads the built binaries to the database, with some integrity checks along the way. That way, it can be guaranteed that the code the mod author has on their Git repo is what the player actually runs, removing the risk of the author uploading binaries built from code different to what they claim it is. cough cough ConfigLib At the same time, I'm not arguing for it to be required, just give the mods that have a proven provenance some badge or something, and let us filter for it. Prior art: JSR.io, NuGet.org 4
Recommended Posts