Topic of signed gems seems to have been last raised in... 2013 https://github.com/rubygems-trust
@stman For #nodejs signed packages were last discussed like in 2018 https://medium.com/@hq/introducing-pkgsign-package-signing-and-verification-for-npm-5b833e0ec2d4
@stman
#python packages could have PGP signatures like forever (twine --sign), but predictably nobody uses it.
There's an active discussion on PEP 458 to sign packages at pypi (centrally) https://discuss.python.org/t/pep-458-secure-pypi-downloads-with-package-signing/2648/123