> It's easier when everyone is doing updates via github/gitlab and leave > the submission form *only* for new scripts. Would cryptographic signatures (GPG) be considered as mentioned earlier? Its peer-to-peer and avoids adding third party gatekeepers.