1. 程式人生 > >Ask HN: Verifying a web app pointing to a specific deployment/commit

Ask HN: Verifying a web app pointing to a specific deployment/commit

I've looked at ways to verify whether a specific deployment is signed and associated with a specific commit hash/deployment, but how do you verify (as a client using the web-app) that the site you are using corresponds to something that can be verified? (i.e. How can a user be sure that the code on the web-server isn't running anything else? If at all even possible)