Code packages like Sojourn need the assurance that the code you downloaded was the code in the open source repo, and that this code is deeply investigated for "naughty bits" and validated...but not by RedHat...by a compensated community governed by a Token Curated Registry. The process would generate IPFS-stored signed and community-certified runtimes, so that anyone using them knows it is the real deal and not pirateware.
Code packages like Sojourn need the assurance that the code you downloaded was the code in the open source repo, and that this code is deeply investigated for "naughty bits" and validated...but not by RedHat...by a compensated community governed by a Token Curated Registry. The process would generate IPFS-stored signed and community-certified runtimes, so that anyone using them knows it is the real deal and not pirateware.