devlooped / SponsorLink

SponsorLink: an attempt at OSS sustainability
https://www.devlooped.com/SponsorLink
MIT License
33 stars 4 forks source link

Improve self-hosting story for signed manifests #146

Closed kzu closed 2 months ago

kzu commented 6 months ago

Instead of assuming other OSS projects will use our infrastructure, assume instead that they (being developers) will instead host their own endpoint for signed manifest generation. This should lower the bar for adoption since they can keep their sponsors information entirely private, while still emitting the manifest server-side and properly signed with their own private key.

This also makes it far more costly for malicious users intending to circumvent SL, since they would need to work around individually each package using it, rather than hacking a single manifest.

Features:

kzu commented 2 months ago

This is all available and documented on main branch now. https://www.devlooped.com/SponsorLink/github.html#sponsorable-backend-self-hosting