On Wed, Apr 15, 2015 at 8:02 AM Greg Weber <
greg@gregweber.info> wrote:
It would be a fundamental shift away from how Hackage does things today. I think the necessary steps would be:
1. Hackage ships all revisions to cabal files somehow (personally, I think it should be doing this anyway).
2. We have a list of trustees who are allowed to edit metadata. The signing work already has to recapture that information for allowed uploaders since Hackage doesn't collect GPG keys
3. Every time a revision is made, the person making the revision would need to sign the new revision
I'm open to other ideas, this is just what came to mind first.
Michael