@bascule ("Tony “Abolish ICE” Arcieri 🦀") retweeted:
@decodebytes ("Luke Hinds") wrote:
@projectsigstore verifying a #rustlang's rustup against a trust root of the sigstore CA / ODIC acc. Only if it passes checks (ensuring tamper free) will it allow execution. This can be done with any script / blob by using a trick with commit -> tag -> release | latest.