Towards ensuring integrity and authenticity of software repositories