hackage-security: Hackage security library

[ bsd3, distribution, library ] [ Propose Tags ]

The hackage security library provides both server and client utilities for securing the Hackage package server (http://hackage.haskell.org/). It is based on The Update Framework (http://theupdateframework.com/), a set of recommendations developed by security researchers at various universities in the US as well as developers on the Tor project (https://www.torproject.org/).

The current implementation supports only index signing, thereby enabling untrusted mirrors. It does not yet provide facilities for author package signing.

The library has two main entry points: Hackage.Security.Client is the main entry point for clients (the typical example being cabal), and Hackage.Security.Server is the main entry point for servers (the typical example being hackage-server).

This is a beta release.

Versions [RSS] [faq],,,,,,,,,,,,,,
Dependencies base (>=4.4 && <5), base64-bytestring (==1.0.*), bytestring (>=0.10.2 && <0.11), Cabal (>=1.12 && <1.25), containers (>=0.4 && <0.6), cryptohash (==0.11.*), directory (>=1.1 && <1.3), ed25519 (==0.0.*), filepath (>=1.2 && <1.5), ghc-prim, mtl (==2.2.*), network (>=2.5 && <2.7), network-uri (==2.6.*), old-locale (>=1.0), parsec (==3.1.*), tar (>=0.4.2 && <0.5), template-haskell, time (>=1.2 && <1.6), transformers (==0.4.*), zlib (>=0.5 && <0.7) [details]
License BSD-3-Clause
Copyright Copyright 2015 Well-Typed LLP
Author Edsko de Vries
Maintainer edsko@well-typed.com
Category Distribution
Uploaded by EdskoDeVries at 2015-08-24T16:55:28Z
Distributions Arch:, Debian:, Fedora:, LTSHaskell:, NixOS:, Stackage:, openSUSE:
Downloads 50962 total (609 in the last 30 days)
Rating (no votes yet) [estimated by Bayesian average]
Your Rating
  • λ
  • λ
  • λ
Status Hackage Matrix CI
Docs available [build log]
Last success reported on 2015-08-24 [all 1 reports]



Manual Flags

Automatic Flags

Are we using base 4.8 or later?


Are we using network-uri?


Use -f <flag> to enable a flag, or -f -<flag> to disable that flag. More info


Maintainer's Corner

For package maintainers and hackage trustees