minisign
homebrew-core
minisign | homebrew-core | |
---|---|---|
12 | 133 | |
1,967 | 13,216 | |
- | 0.5% | |
4.8 | 10.0 | |
about 1 month ago | 6 days ago | |
C | Ruby | |
GNU General Public License v3.0 or later | BSD 2-clause "Simplified" License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
minisign
- Ask HN: What are your favorite tiny, single purpose tools?
- Minisign A dead simple tool to sign files and verify signatures
-
PGP signatures on PyPI: worse than useless
There are alternatives, minisign and signify.
-
Can a program be the only thing able to have access to a private key?
You don't have to attach identities to public and private keys. If all you need it for is signing, then check out minisign.
-
How should I encrypt files for sharing over the internet?
If you need signatures, minisign is a similar hard-to-misuse program.
-
Beginner: how to do basic cryptography for a blog
In your case, use a tool such as https://jedisct1.github.io/minisign/ to do signing/verification. GPG is another choice which is very common. It will produce a "signature" which can be embedded alongside your posts verifying that the text of the post was endorsed by someone bearing the given public key.
-
Is it worth it to make the move to ProtonMail & VPN?
Claiming it's not ancient because Linux desktop distributions still use it for signing packages is a very odd argument. Most Cryptography experts (note: I'm not talking about programmers, IT professionals or people who know a thing or two about cryptography, I mean actual cryptographers) would agree that we should start using something like signify or minisign instead of the bloated mess that is GPG for signing package repositories.
-
Hacker News top posts: Dec 23, 2021
minisign\ (5 comments)
- minisign
- Show HN: Pagesign – A Python Wrapper for Age and Minisign
homebrew-core
-
Is Go Used in Production more than Rust ?
$ brew info eza ==> eza: stable 0.18.13 (bottled) Modern, maintained replacement for ls https://github.com/eza-community/eza Not installed From: https://github.com/Homebrew/homebrew-core/blob/HEAD/Formula/e/eza.rb License: MIT ==> Dependencies Build: pandoc ✘, pkg-config ✔, rust ✘ Required: libgit2 ✘ ==> Analytics install: 12,792 (30 days), 38,295 (90 days), 68,375 (365 days) install-on-request: 12,790 (30 days), 38,293 (90 days), 68,375 (365 days) build-error: 0 (30 days)
-
GitHub Disabled the Xz Repo
Is disabling the compromised repo the typical GitHub policy? My concern is there are monorepos used by package managers, like brew, that are a collection of thousands of projects [1]. These monorepos seem like a prime target for attack and if GitHub disables one because a malicious commit was merged then you've taken down an entire ecosystem.
[1] https://github.com/Homebrew/homebrew-core
-
Backdoor in upstream xz/liblzma leading to SSH server compromise
> Correct. Though we do not appear to be affected, this revert was done out of an abundance of caution.
[1] https://github.com/Homebrew/homebrew-core/pull/167512
-
Pyenv – lets you easily switch between multiple versions of Python
> right, but now you know even less about your setup when you some roadblock
This is the same with a binary though. And with homebrew, you can't follow patches or flags used or if they change.
- https://github.com/Homebrew/homebrew-core/blob/c964ad7fa53ad...
- Apple curl security incident 12604
-
Cowsay
definitely be careful about using fortune in a corporate environment or public space if you don't know what dat files you are using or you might just get an extremely unwelcome surprise.
I was practicing a presentation and used to use "fortune" all the time. I forget exactly what it output but I remember being absolutely mortified about what could have happened if that had popped up during an internal company tech talk.
Kudos to brew for keeping unsuspecting people safe
https://github.com/Homebrew/homebrew-core/commit/3fb3c4c3e55...
-
Ask HN: Trouble with a Stargate
I'm sorry to be asking this as I find it a bit silly, but it's blocking my PR [3], so could a few of you star the project on Github [1] to get my PR to run?
[1] https://github.com/laktak/chkbit-py
[2] https://brew.sh
[3] https://github.com/Homebrew/homebrew-core/pull/160018
- Simulate an Ubuntu-like VM inside macOS
- When open source platforms are worse than closed source
- Homebrew Rejects the Idea for Post-Install Notes
What are some alternatives?
signify - OpenBSD tool to sign and verify signatures on files. Portable version.
yt-dlp - A feature-rich command-line audio/video downloader
age - A simple, modern and secure encryption tool (and Go library) with small explicit keys, no config options, and UNIX-style composability.
asdf-python - Python plugin for the asdf version manager
age-plugin-yubikey - YubiKey plugin for age
HomeBrew - 🍺 The missing package manager for macOS (or Linux)
ed25519 - Minimal ed25519 Haskell package, binding to the ref10 SUPERCOP implementation.
homebrew-php - :beer: Homebrew tap for PHP 5.6 to 8.4. PHP 8.4 is built nightly.
kyber
osxfuse - FUSE extends macOS by adding support for user space file systems
mkp224o - vanity address generator for tor onion v3 (ed25519) hidden services
homebrew-cask-versions - 🔢 Alternate versions of Casks