Jump to content

Recommended Posts

Posted

Mod DB should support mod provenance, that is a way to attest that the mod we download is build from the exact code on Github/Gitab/Codeberg/whatever.

A build function should exist that builds the code and uploads the built binaries to the database, with some integrity checks along the way. That way, it can be guaranteed that the code the mod author has on their Git repo is what the player actually runs, removing the risk of the author uploading binaries built from code different to what they claim it is. cough cough ConfigLib

At the same time, I'm not arguing for it to be required, just give the mods that have a proven provenance some badge or something, and let us filter for it.

Prior art: JSR.io, NuGet.org

  • Like 4
×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.