Hex包管理器是否支持端到端认证?Elixir包完整性与真实性验证咨询
Great question—securing your dependency chain is critical, and it’s smart to dig into this kind of protection. The short answer is yes, Hex absolutely supports cryptographic verification of package integrity and authenticity, though it uses a different system than OpenPGP.
Here’s how it works in practice:
- Hex relies on Ed25519 digital signatures (a modern, secure elliptic curve algorithm) instead of OpenPGP. This support launched back in Hex 0.13.0 and is enabled by default for all users, no extra setup required.
- When a package author publishes to Hex, they’re required to sign their package with their Ed25519 key pair (Hex walks first-time authors through generating this pair during their initial publish).
- Every time you pull packages via
mix deps.getor the Hex CLI, the client automatically verifies the package’s signature against the author’s public key stored in Hex’s trusted registry. This guarantees the code you install is exactly what the author released—no tampering in transit or via the central repository. - Beyond individual packages, Hex also signs its entire package index. The client checks this index signature too, so you can trust the list of available packages and their versions hasn’t been altered.
If you want to manually verify a package’s signature for extra peace of mind, run this command:
hex package verify <package_name> <package_version>
This will confirm the package’s signature is valid and that the author’s public key is trusted by Hex’s system. You can also manage trusted keys manually with commands like hex key add, though the default setup already links author identities to verified accounts (like GitHub) to keep things secure.
While it’s not OpenPGP, Ed25519 offers strong security with better performance than older algorithms, making it a great fit for the Elixir/Erlang ecosystem. The end goal is identical: you’re protected against tampering attacks on Hex’s central storage.
内容的提问来源于stack exchange,提问作者aef

