Package Author Identity through Social Proofs

1 · Phil Haack · May 10, 2019, midnight
In my post on Why NuGet Package Signing Is Not Yet For Me I noted… as a NuGet consumer, there’s no way, within reason, that I can take advantage of package signing to make my environment more secure. At least not yet. For the most part, Microsoft implemented package signing in NuGet to comply with its own internal security policies. But for the rest of us, it has little benefit today. So what would I propose? Perhaps we can get a little help from our friends! No, not those friends. Your frien...