Thanks for all the suggestions so far guys.
Looks the the first order of business is building a token generator which can then be used for our current upload api and the packager / webhook I'm working on.
As for the pkgmeta.yaml, that looks fine to implement. I'd almost rather go with a pkgmeta.json but can do yaml to keep things the same.
|