Taffer 🇨🇦 :godot:<p>I've made a small demo script for PGP signing a Python file; this technique could be easily extended to any other scripting language that supports block comments.</p><p><a href="https://codeberg.org/Taffer/pygp-sign" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">codeberg.org/Taffer/pygp-sign</span><span class="invisible"></span></a></p><p>Installers could verify the `.py` files in a package, and a runtime could also verify them at import time (hopefully with some key caching involved).</p><p><a href="https://mastodon.gamedev.place/tags/python" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>python</span></a> <a href="https://mastodon.gamedev.place/tags/pgp" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>pgp</span></a> <a href="https://mastodon.gamedev.place/tags/gpg" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>gpg</span></a> <a href="https://mastodon.gamedev.place/tags/codesigning" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>codesigning</span></a> <a href="https://mastodon.gamedev.place/tags/signatures" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>signatures</span></a> <a href="https://mastodon.gamedev.place/tags/SoftwareSuppyChain" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SoftwareSuppyChain</span></a></p>